Legal
Privacy Policy
Document version 1.0 · Effective 1 July 2026 · Last reviewed 2026-Q3 · Questions privacy@saptiva.com
The short version.
Data your organization runs through the Saptiva AI platform is your data. We handle it as a processor, on your documented instructions, under the Data Processing Agreement we sign with you. It is never used to train models.
This page governs the personal data we collect through this website, our published inboxes, and our hiring process. That is a short list, and section 003 states all of it.
This site runs no analytics, no advertising pixels, and no third-party trackers. It sets one cookie, and that cookie remembers whether you read the site in English or Spanish.
001 / Scope
Two kinds of data. Two different documents.
Almost every complaint about a privacy policy comes from the same confusion: a single document tries to cover the vendor's marketing list and the customer's production data at once, and ends up describing neither honestly. We separate them, because the roles are genuinely different and so are the rules that apply.
Platform · Customer Data
Everything your organization processes through Saptiva Studio and frIdA: the documents, records, prompts, outputs, and the personal data of your own customers, employees, or students inside them.
You are the controller. Saptiva AI is the processor. Governed by your Data Processing Agreement, not by this page. Section 002 describes how we behave in that role.
Website · Personal Data
What you send us through this site, our published inboxes, and our hiring process, plus the technical data any web request produces.
Saptiva AI is the controller. Governed by this page. Section 003 lists all of it, without abbreviating.
If you are reading this because your bank, insurer, or university runs Saptiva AI and you want to know what happens to your personal data there, section 002 tells you how we behave, and section 007 tells you where to send the request. The answer to that request belongs to the institution, not to us. That is not evasion. It is what being the processor means.
002 / Customer Data
Your data stays yours. Including from us.
We act only on your instructions
As processor, we process Customer Data for one reason: to deliver the service you contracted, in the way your configuration says. We do not process it for our own purposes, we do not enrich it, we do not analyze it across customers, and we do not derive products from it. The Data Processing Agreement makes that binding and adds the detail this page cannot: the specific instructions, the subprocessor list for your deployment, the audit rights, and the notification terms.
Customer Data is not training data
We do not use Customer Data to train, fine-tune, or evaluate any model for our benefit or anyone else's. Not our models. Not a model provider's. Not an aggregate, an embedding, or a derived dataset that outlives your deployment.
Where you choose to fine-tune a model on your own data, the resulting weights are treated as your data and stay inside your deployment environment. Saptiva AI does not copy them out. In an air-gapped deployment there is no external path at all. In an on-premise deployment the platform still reaches out for its own updates, but no path carries Customer Data or your model weights off your infrastructure.
Where it runs is your decision, and it is recorded
Residency is a property of the architecture, not a promise in a slide. Each data class is assigned the environments it may run in, frIdA routes accordingly, and the route lands in the audit record. Deployments run in public cloud, in-country regions, private cloud, on your own hardware, or fully air-gapped. Your configuration decides which. For deployments where residency is a defining requirement, the physical region, the legal jurisdiction, and the contractual residency commitment are written into your agreement.
What we can reach, and what we cannot
Saptiva AI personnel hold no standing access to customer production data. Operational intervention requires your authorization, is bounded in time, is tied to a specific incident or work order, and is captured in the same audit record as every other action in your environment, on the same terms. Our access to your systems is as auditable to you as your own users' access.
Subprocessors
Who else touches the data depends entirely on how your deployment is built. An air-gapped deployment has no subprocessors. A public cloud deployment inherits the cloud provider you selected. An on-premise deployment may have none at all. For each engagement we publish the active subprocessor list in the DPA and notify you in advance of any change, so that you can exercise the rights your agreement gives you before it takes effect.
Return and deletion
Retention inside your deployment follows your schedule, not ours. When the agreement ends, Customer Data is returned or deleted on the terms it sets. Where the deployment sits on your own infrastructure, there is nothing for us to return, because it never left.
The claim on this page is not the commitment. The commitment is in the agreement. If this page and your Data Processing Agreement ever say different things, the agreement governs, and we would like to know about the discrepancy: privacy@saptiva.com.
003 / Website Data
Everything this website collects. The whole list.
This is not a summary. It is the complete inventory of personal data Saptiva AI collects as controller through this site and our inboxes.
| What we collect | Why | How long |
|---|---|---|
| The get started form: your name, work email, organization, and your answer to "where does your AI run today?" Sent with it: the page you submitted from, a timestamp, and the country code our host derives from your IP. | So an engineer can read it and reply within 48 hours. | It is delivered as an email to our team inbox and lives there. There is no CRM behind the form and no database of submissions. |
| Whatever you write to a published inbox: hi@, partners@, hr@, press@, security@, legal@, privacy@, regulacion@ | To answer you, from the team that can act on it. | As long as the conversation is live or useful, then deleted with the thread. |
| Applications and CVs sent to hr@saptiva.com | To evaluate you for a role and talk to you about it. | Through the hiring process. Longer only if you ask us to keep you in mind. |
| Technical request data at our edge: IP address, user agent, the page requested, the country code our host derives from the IP, and a timestamp | To deliver the page to you and to absorb abuse and denial of service traffic. | Short-lived operational logs held by our hosting provider. The country code is the one element that travels further: it is attached to the form email described above. Nothing else is copied out or joined to anything. |
| One cookie named lang, and the same value in your browser's local storage | To remember whether you read the site in English or Spanish. Set only when you use the EN/ES switch. | One year, or until you clear it. Clearing it costs you nothing but the language preference. |
One thing we do not control, said plainly
This site loads its typefaces from Google Fonts. That means your browser requests those font files from Google's servers, and that request reveals your IP address and user agent to Google, as it does on a large share of the web. We get nothing from it and we do not see it. We are telling you because it is true and almost nobody says it. If we move the fonts onto our own domain, this paragraph goes away.
What this site does not do
- No analytics. No page-view counter, no session recording, no heatmaps, no funnels.
- No advertising pixels and no remarketing tags. Nothing on this site reports to an ad network.
- No third-party trackers and no cross-site tracking of any kind.
- No profiles. We do not build a picture of who you are out of how you browse.
- No automated decision-making about you, and no scoring of visitors.
- No sale of personal data, and no sharing of it for anyone else's marketing. Not now, and if that ever changes it changes here first, in advance.
- No consent banner, because there is nothing to consent to. The single cookie is functional and does nothing else.
You can verify most of this yourself in about a minute. Open your browser's network tab and load any page on this site. The only external hosts you will see are the font servers.
004 / Purposes
What we use it for, and what you can refuse.
Primary purposes
These are the purposes that give rise to the relationship. Without them we cannot do the thing you contacted us for.
- Reply to you, and continue the conversation you started.
- Evaluate, scope, and support a deployment, including the technical and security review your team will run on us.
- Assess your application if you are applying for a role.
- Deliver this website, keep it available, and defend it against abuse.
- Meet an obligation the law places on us, or establish and defend a legal claim.
Secondary purposes
There is one, and it is optional: occasionally telling you something about the platform we think is relevant to what you asked us. We do not run a marketing automation sequence, and we do not add you to a list because you filled in a form.
To refuse the secondary purpose, reply to any message from us saying so, or write to privacy@saptiva.com. Refusing it has no effect on anything else: we still answer your questions, and it does not affect any commercial relationship. No form, no account, no unsubscribe maze.
005 / Legal basis
Why we are allowed to hold it.
This notice is written to satisfy Mexican personal data protection law, which requires that a privacy notice identify the responsible party and its registered address, and state what is collected, for what purposes, and how you exercise your rights. Section 012 identifies the responsible party and both of our registered addresses. Sections 003, 004 and 007 carry the rest.
Where a visitor or applicant is in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following bases: your consent, where you gave it; the steps taken at your request before entering into a contract, where you asked us to evaluate a deployment; our legitimate interest in answering our own correspondence, hiring, and keeping this site up and secure, which is a narrow interest and is not overridden by your rights given how little we collect; and legal obligation where one applies.
For Customer Data, the basis is your instruction as controller, recorded in the Data Processing Agreement. We do not choose a basis for your processing. You do.
006 / Security
How we protect it, control by control.
Security is a property of a specific deployment, not a badge on a vendor. A customer running air-gapped has a materially different envelope than one running in public cloud, and both are valid. What follows is the capability. Which capabilities are engaged in your deployment is set by your configuration, applied by frIdA, and visible in your audit record. The full document, maintained and versioned, is the Security & Compliance page.
| Control | Posture |
|---|---|
| Data in transit | TLS 1.3 for all external traffic. Mutual TLS between services inside a deployment. No unencrypted network paths in production. |
| Data at rest | AES-256 for stored data, scoped per tenant. Storage-layer encryption is additive to application-layer encryption for sensitive fields. |
| Key custody | Customer-held keys are supported in in-country, private, and on-premise deployments, with HSM integration available. In public cloud mode, keys are managed through the cloud provider's KMS under your own key policies. Automated rotation on a configurable schedule, ninety days by default for data-at-rest keys, and every rotation event lands in the audit record. |
| Identity | SAML 2.0 and OIDC against your own directory. Saptiva AI does not maintain a separate identity provider for the production users of your deployment. |
| Access | Role-based, scoped to the capability a task actually needs. A credit officer's session does not see KYC data unless that is explicitly permitted. MFA required for administrative access and for production workloads touching regulated data. |
| Our own access | No standing access to customer production data. Intervention requires your authorization, is bounded in time, is tied to a named incident or work order, and appears in your audit record on the same terms as everything else. |
| The audit record | Every frIdA dispatch writes a signed, immutable record: what ran, on what data, under which configuration version, authorized by which identity, with what result. Tampering breaks the signature chain. Records are retained inside your jurisdiction, under your retention schedule, and export in structured form for your SIEM. |
| This website | Served over HTTPS. No third-party scripts, no tag manager, no embedded widgets. The only external requests a page makes are for typefaces. |
Certifications, stated honestly
Saptiva AI does not yet hold a completed SOC 2 Type II attestation. We are in the formal readiness and assessment phase with a qualified assessor, and we will publish the attestation date when it is signed. ISO 27001 is in scope for the following fiscal year. We hold a CSA STAR Level 1 self-assessment, our internal control framework maps to the NIST Cybersecurity Framework, and our data handling is aligned to GDPR where a customer carries GDPR-scope obligations.
We say this here, on the privacy page, for the same reason we say it on the security page: a compliance team should not discover it at procurement. If your framework requires a completed attestation before onboarding a vendor, we can share our current readiness artifacts under NDA and put your compliance team in front of our security lead.
When something goes wrong
We notify within 72 hours of a confirmed security incident affecting your environment or your data, and shorter windows are available by contract where your framework requires them. Our security leadership engages your incident response team directly, without routing through sales or account management while an incident is live. A structured post-incident report follows, within the period your agreement sets: sequence of events, impact, root cause, remediation, and the preventive changes we made.
Reporting a vulnerability
If you have found a security issue in Saptiva AI, write to security@saptiva.com. That inbox goes to our security lead and is monitored continuously. We welcome good-faith research. What counts as good faith, and our commitment not to pursue a researcher who meets it, are set out once in section 011 of the Terms of Use. The Security & Compliance page carries the full posture.
007 / Your rights
What you can ask for, and how.
Under Mexican personal data protection law you may ask for access to the personal data we hold about you, rectification of it when it is inaccurate or incomplete, cancellation when it should no longer be held, and you may object to a given use of it. You may also revoke a consent you gave, and limit the use and disclosure of your data.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you additionally have the rights to erasure, to restriction of processing, to data portability, and to lodge a complaint with your supervisory authority. We would rather you raised it with us first, but that right is yours regardless.
How to exercise them
Write to privacy@saptiva.com. Tell us what you want and give us enough to locate the data and confirm the request is genuinely yours. A person answers, inside the period the applicable law provides and in practice faster than that. There is no charge and no form. If we cannot do what you asked, we tell you which part we cannot do and why, rather than declining in the abstract.
If your data sits inside a customer's deployment, the request belongs to that institution: they are the controller and we are the processor, and answering on their behalf would be exactly the overreach this page rules out. Write to us anyway and we will tell you who to ask and help them respond.
008 / Sharing
Who else receives data, and who never does.
For this website and our inboxes, the complete list of third parties is three, and each one is doing an unglamorous, necessary job:
| Who | What they do |
|---|---|
| Cloudflare | Hosts and serves this site, and absorbs abusive traffic at the edge. Sees request data as described in section 003. |
| Resend | Delivers the get started form to our inbox as an email. Receives what you typed into that form and keeps a copy in its own delivery logs, under the retention configured on our account. |
| Google Fonts | Serves the typefaces. Sees your IP and user agent when your browser fetches a font, as described in section 003. |
That is the list. No data brokers, no enrichment services, no advertising networks, no analytics vendors, no lead-scoring platforms. Subprocessors for the platform are a separate matter and are governed by your DPA, as section 002 describes.
International transfer
The infrastructure serving this website is global by design, so a page request may be answered from an edge location outside your country. That is delivery, not export: nothing is stored there for us. Where Customer Data is concerned, the opposite is true and deliberate: it goes where your configuration says it goes, and nowhere else. That is the entire point of the product.
Requests from authorities
We disclose personal data to an authority only where valid legal process compels it, and we read the request rather than assuming it is valid. Where the request touches a customer's data, we notify that customer promptly and give them a copy so they can respond, unless we are legally barred from telling them. We do not volunteer data, and we do not treat an informal request as an order.
009 / Retention
We keep it while it is doing something.
Website and inbox data is kept while the conversation is live or useful, and then deleted with the thread. Hiring data is kept through the process, and beyond it only if you asked us to. Operational request logs are short-lived and held by our hosting provider. Anything the law requires us to keep, we keep for exactly as long as it requires and no longer.
Retention of Customer Data inside a deployment follows the customer's schedule, and audit records follow the retention their own framework sets. We do not impose a retention period on a customer's data, and we do not keep a shadow copy after one.
010 / Minors
This is not a consumer service.
Saptiva AI sells to institutions, not to individuals. This website is directed at people evaluating infrastructure on behalf of an organization, and we do not knowingly collect personal data from minors through it. If you believe a minor has sent us personal data, write to privacy@saptiva.com and we will delete it.
Where a customer's deployment processes data about minors, for instance a university operating student services, that processing is the institution's, under its own framework and its DPA with us. Our obligations there are the processor obligations in section 002.
011 / Changes
This page is versioned, like the security page.
When this notice changes, the version number and the review date at the top change with it. A change that narrows what we do takes effect when it is published. A change that widens it, meaning we would collect something new or use it for something new, is announced before it takes effect, and where the law requires your consent we ask for it rather than assuming it.
We do not reserve the right to change this notice silently, and we do not consider your continued use of the site to be agreement to a new version.
012 / Contact
A person reads these.
Saptiva AI operates through two entities. For the purposes of this notice, the party responsible for the personal data described in section 003 is Saptiva, S.A.P.I. de C.V.
| Entity | Registered address |
|---|---|
| Saptiva, S.A.P.I. de C.V. Mexico. Responsible party for this notice. | Blvd. P. Insurgentes 3356, T1 P8 Int. 6, Cumbres del Campestre, C.P. 37128, Leon, Guanajuato, Mexico |
| Saptiva, Inc. United States. | 400 N McColl Rd, Suite A, McAllen, Texas 78501, United States |
The team works from Mexico City. The addresses above are the registered addresses of each entity, which is what this notice is required to publish.
| Reason | Address |
|---|---|
| Privacy questions, and any request under section 007 | privacy@saptiva.com |
| Security concerns, vulnerability reports, and compliance questionnaires | security@saptiva.com |
| Agreements: the MSA, the DPA, and the rest of the contract set | legal@saptiva.com |
Related reading: the Security & Compliance page for controls, residency, subprocessor categories, and our certification posture, and the Terms of Use for what governs this website.
