1. Information We Collect
We collect information you provide directly to us, information generated through your use of our Services, and information obtained from third-party sources. The categories of information we collect include:
1.1 Account Information
When you register for a SenAsset account, we collect your name, email address, company name, job title, phone number, and billing information including payment card details (processed securely via Stripe). We also collect your chosen password in hashed form.
1.2 Asset and Usage Data
We collect all data you input into our platform, including asset records, location data, assignment histories, maintenance logs, custom fields, file attachments, and audit trail entries. This data is your property and is stored on your behalf.
1.3 Automatically Collected Information
When you use our Services, we automatically collect technical information including: IP address, browser type and version, operating system, referring URLs, pages visited, time spent on pages, click events, device identifiers, and session identifiers. We use this data to maintain security, improve performance, and understand usage patterns.
1.4 Communications
If you contact us for support or submit feedback, we retain the content of your communications along with your contact details. We may also keep records of calls with our sales or support teams with your consent.
2. How We Use Information
We use the information we collect to:
- Provide, operate, maintain, and improve our Services
- Process transactions and send related information including purchase confirmations and invoices
- Send technical notices, updates, security alerts, and support and administrative messages
- Respond to your comments, questions, and customer service requests
- Send marketing communications (where you have consented or where permitted by law)
- Monitor and analyze trends, usage, and activities in connection with our Services
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
- Personalize and improve your experience and provide content or features that match your profile
- Comply with applicable laws and regulations
- Carry out any other purpose described to you at the time the information was collected
We process your personal data on the legal bases of: (a) performance of a contract when we provide you with the Services; (b) your consent where required by law; (c) our legitimate business interests, including operating and improving our Services, fraud prevention, and direct marketing; and (d) compliance with legal obligations.
3. Information Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties. We may share your information in the following circumstances:
3.1 Service Providers
We share information with third-party vendors and service providers that perform services on our behalf, including cloud infrastructure (AWS), payment processing (Stripe), email delivery (SendGrid), error monitoring (Sentry), and analytics (Mixpanel). These providers are contractually bound to use your data only as directed by us.
3.2 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of SenAsset, our customers, or the public.
3.3 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will notify you via email and a prominent notice on our Services prior to such transfer.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our Services. We also retain information as necessary to comply with legal obligations, resolve disputes, enforce agreements, and support business operations.
When you close your account, we will delete or anonymize your personal information within 90 days, unless we are required by law to retain it for a longer period. Asset and operational data is archived for 12 months before deletion to allow for potential account reactivation.
Backup copies of your data may persist in our backup storage for up to 30 days following the deletion of your account. These backups are encrypted and inaccessible except in the event of a disaster recovery scenario.
6. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information. These rights may include:
Right of Access
Request a copy of the personal information we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete personal information.
Right to Erasure
Request deletion of your personal information in certain circumstances.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Right to Restrict
Request that we restrict the processing of your personal information.
To exercise any of these rights, please contact us at privacy@senasset.com. We will respond to your request within 30 days. For more information about your rights under GDPR, please see our GDPR page.
7. Data Security
We take the security of your information seriously and implement industry-standard technical and organizational measures to protect it. These measures include AES-256 encryption at rest, TLS 1.3 encryption in transit, access controls based on the principle of least privilege, regular penetration testing, and SOC 2 Type II compliance.
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security. Please review our Security page for more details.
8. International Data Transfers
SenAsset is headquartered in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Enterprise customers may request a Data Processing Agreement (DPA) by contacting privacy@senasset.com.
9. Children's Privacy
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that a child under 16 has provided us with personal information, we will take steps to delete such information. If you believe that a child under 16 has provided us with personal information, please contact us at privacy@senasset.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we will send you an email notification. Your continued use of our Services after any changes take effect constitutes your acceptance of the revised Privacy Policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our privacy practices, please contact our Privacy Team: