Skip to main content

Privacy Policy

Last updated: October 4, 2026

1. Data Controller

The data controller for personal data collected on sens-ai.biz and through Sens-AI services is:

2. Data Collected

In the course of providing our AI chatbot services, we collect the following categories of data:

  • Identification data: name, professional email address
  • Account data: login credentials, user preferences
  • Conversation data: messages exchanged with the AI chatbot, conversation history
  • Phone number: the caller's number on the telephone channel, or a number given during a conversation, used to identify the person and to let an agent call them back; kept for 90 days, like the conversation it belongs to. The number assigned to an agent belongs to Sens-AI and is provided as part of the subscription.
  • Technical data: IP address, browser type, cookie data
  • Usage data: service usage statistics, connection logs

3. Purpose of Data Processing

Your personal data is processed for the following purposes:

  • Providing and operating the AI chatbot service
  • Managing your user account
  • Improving the quality of our services
  • Technical support and customer assistance
  • Service-related communications (updates, maintenance)
  • Compliance with legal obligations

5. Data Retention Periods

Your personal data is retained for the following periods:

Data TypeRetention Period
Conversation data90 days from the last exchange
Account dataUntil account deletion
Technical logs30 to 90 days
Cookies13 months maximum

6. Third-party Data Processors

To operate our services, we use the following GDPR-compliant data processors:

ProcessorServiceLocation
CloudflareHosting, CDN, file storage, securityEU (European servers)
TursoDatabaseEU (Ireland)
UpstashCache, job queue, semantic searchEU (Frankfurt)
Mistral AIAI language modelEU (France)
CreemPayment platform (Merchant of Record)EU
Loops.soTransactional and marketing emailUnited States (SCCs)
Telnyx LLCTelephony — phone number allocation and call routing for the voice channelUnited States (SCCs)

Your conversation data is hosted within the European Economic Area (EEA). Hosting, database, file storage and the AI language model are all located in the EU.

The following transfers outside the EEA exist, all governed by the European Commission's Standard Contractual Clauses (SCCs): our email delivery provider Loops.so is established in the United States and receives only the data required to send a message — email address, name and communication preferences — with no conversation content; some of our infrastructure providers store your data in the EU but may access it from the United States as part of their technical support; payments are routed through international payment networks, which are additionally PCI-DSS certified; and our telephony provider Telnyx LLC (United States) routes voice channel calls and hosts the allocated phone numbers. The per-provider detail is set out in Article 7 of our data processing agreement.

7. Your Rights

Under the GDPR, you have the following rights:

  • Right of access: obtain confirmation that your data is being processed and receive a copy
  • Right to rectification: correct inaccurate or incomplete data
  • Right to erasure: request deletion of your personal data
  • Right to data portability: receive your data in a structured, machine-readable format
  • Right to object: object to the processing of your data on legitimate grounds
  • Right to restriction: request restriction of the processing of your data

To exercise these rights, contact us at: [email protected]

You also have the right to lodge a complaint with the CNIL (French Data Protection Authority): www.cnil.fr

8. Cookie Policy

Our website uses cookies to ensure proper functioning and improve your user experience.

Types of cookies used:

  • Essential cookies: necessary for the website to function (session, consent preferences)
  • Analytical cookies: help us understand how the site is used so we can improve it

You can change your cookie preferences at any time through your browser settings. Deleting essential cookies may affect the website's functionality.

9. Google user data (Google Calendar and Gmail)

When a customer connects their Google Calendar account (appointment booking) or their Gmail mailbox (e-mail channel) to Sens-AI, we access some data of that account through Google APIs, with their explicit authorization. This connection is optional and can be removed at any time.

Data accessed

  • Account identity (openid, email): the Google account's technical identifier and e-mail address, to display the connected account.
  • Calendar list (calendar.calendarlist.readonly): the calendars you own, to choose the one that receives bookings, and to check that Sens-AI still has access to it before freeing a slot.
  • Availability (calendar.freebusy): only the busy time ranges of the chosen calendar, without the title or content of your events, to offer free slots.
  • Events created by Sens-AI (calendar.events.owned): creation of the appointment booked by a visitor; read-back of the events created by Sens-AI only (status, times and the guest's response) to confirm the booking and keep your availability accurate when an appointment is cancelled, moved or declined in Google; deletion of the event when you cancel or release the appointment from the dashboard (Google then notifies the visitor), or when the guest has declined the invitation. Sens-AI does not read, modify or delete any other event.
  • Change notifications (calendar.events.owned): Sens-AI subscribes to the notifications Google sends when the chosen calendar changes. They contain no event content and only trigger the read-back above.

How we use it

This data is used only to offer time slots, to record the appointments your visitors request, then to follow them (cancellation, move, refusal) and to delete them in the cases described above. For each appointment, Sens-AI sends Google only:

  • Title: the appointment type name and the visitor's name;
  • Guest: the visitor's e-mail address, verified with a one-time code, and their name — Google sends them the invitation;
  • Description: a note that the appointment was booked through your assistant, and the visitor's phone number if they gave it;
  • Location: the text you entered for this appointment type, if any;
  • Times: start and end date and time, and time zone;
  • Technical identifier: an appointment identifier, derived from the agent and the booking, that prevents duplicates, and a private technical property, invisible to guests, that marks the event as created by Sens-AI.

Storage, retention and deletion

  • Google access tokens are encrypted (AES-256-GCM) and stored in our database in the EU (Ireland).
  • When you disconnect the calendar or delete your account, we revoke the authorization with Google and immediately erase the tokens and the account's e-mail address. The Google account's technical identifier is deleted once no appointment, configuration, follow-up or pending deletion refers to it any more, and at the latest when the account is deleted.
  • You can also remove access from your Google account (myaccount.google.com/permissions): the tokens become unusable and we erase them at the next attempt to use them.
  • Appointments recorded by Sens-AI (visitor's name, e-mail address and phone number, type and time slot) are deleted automatically by a periodic purge once 90 days have passed since the appointment ended, and when the agent or the account is deleted.
  • To follow appointments, Sens-AI keeps the identifier of the followed calendar, the state of the notifications and, for each requested deletion, the event's technical identifier until it is deleted at Google; if the deletion keeps failing, the Sens-AI team is alerted after 7 days. This data is erased once it no longer serves any appointment or pending deletion, and at the latest when the account is deleted.
  • Apart from the deletions described above (a cancellation or release you request from the dashboard, a guest's refusal), Sens-AI deletes nothing in your Google Calendar: appointments already created and the invitations visitors received stay there after you disconnect, delete the agent or the account, or after the 90-day deletion. They are yours and your Google account's.

Gmail (e-mail channel)

  • Reading (gmail.readonly): Sens-AI watches the connected inbox and reads newly received messages (sender, subject, content, attachments) so that the assistant can answer them. Messages identified as coming from automated senders (newsletters, "no-reply" addresses) and messages sent by the mailbox itself are ignored.
  • Sending (gmail.send): replies written by the assistant or by your team are sent from the connected mailbox, in the thread of the received message.
  • Processing: each retained message becomes a conversation in your Sens-AI workspace. Its content is processed by our artificial intelligence model (Mistral AI, EU) only to draft the reply; it is kept for the conversation retention period (section 5).
  • Storage and deletion: access tokens are encrypted and stored in the EU. When you disconnect the mailbox, we revoke the authorization with Google and stop all reading.

Sharing and commitments

  • We do not sell this data and do not use it for advertising or to train artificial intelligence models.
  • It is shared with third parties only as needed to operate the service (sub-processors listed in section 6), to your own Google Calendar when you connect it, or when required by law.
  • No Sens-AI staff reads it, except with your consent, for security purposes, or to comply with a legal obligation.

Commitment:

Sens-AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10. Contact

For any questions regarding the protection of your personal data, please contact us:

View our Data Processing Agreement (DPA)