Last updated 29 August 2026
This policy explains what Senpiper Technologies India Private Limited (“Senpiper”, “we”) does with personal data on senpiper.com and in the systems we build and operate for clients. It covers two very different situations, and the difference matters.
Two roles, kept separate
On this website and in our own sales and support operations, Senpiper is the controller: we decide what is collected and why.
Inside a client deployment, Senpiper is a processor. The client is the controller. We handle personal data only on their written instructions, under a data processing agreement, and only for as long as that agreement runs. Where a deployment runs on the client’s own infrastructure, we may hold no client data at all.
What we collect on this website
- Contact details you send us: name, organisation, work email, phone number and anything you write in a message or a form.
- Records of our correspondence, so the next person you speak to knows the history.
- Basic technical data your browser sends: IP address, user agent, pages requested and timestamps, used to keep the site available and secure.
We do not sell personal data, and we do not use it to train models.
Why we use it
- To answer your enquiry and to prepare a proposal, sizing or evaluation.
- To meet a legal, tax or contractual obligation.
- To keep our own systems secure and to investigate misuse.
Where the law requires consent, we ask for it and you can withdraw it. Otherwise we rely on legitimate interests or on the performance of a contract.
Who else sees it
Our own staff, on a need-to-know basis. Service providers who host our website, send our email and keep our records — each under contract, each restricted to those purposes. Regulators, auditors or courts where we are legally required to disclose. Nobody else.
Where it is held
Website and corporate data is held on infrastructure in India and, for some services, in other jurisdictions. Where personal data moves across a border, we use the transfer mechanisms the applicable law provides, including standard contractual clauses.
Client deployments are different by design: the client chooses the environment, and models, documents, prompts, embeddings and logs stay inside it.
How long we keep it
Enquiry and correspondence records: while the relationship is live, and afterwards for as long as we need them for legal, tax or audit reasons. Technical logs: a short retention period, measured in weeks or months, unless an incident requires us to keep them longer. Client data under a processing agreement: for the term set in that agreement, then deleted or returned.
Your rights
Depending on where you are, you may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to our use of it, or port it elsewhere. Under India’s Digital Personal Data Protection Act, 2023 you may also nominate someone to exercise these rights on your behalf. Under the GDPR you may complain to your supervisory authority.
If the data sits inside a client deployment, the client is the controller: we will pass your request to them and support them in answering it.
Security
Encryption in transit and at rest, role-based access, logged administrative action, and separation between client environments. Our security posture, certifications and audit reports are available to prospective clients under NDA.
Children
This website is aimed at organisations, not individuals, and we do not knowingly collect data from children.
Changes
If we change this policy we will update the date above. Material changes will be notified to clients through the contact route in their agreement.
Contact
Write to privacy@senpiper.com, or to Senpiper Technologies India Private Limited, Site No. B-15, Sector 32, Gurgaon, Haryana 122001, India.