1. Who we are
Sense-Optimization ("we", "us", "our") is the data controller responsible for your personal data in connection with the Sense-Optimization software and website (the "Service").
- Legal entity: [COMPANY NAME]
- Registered address: [REGISTERED ADDRESS]
- Registration number: [REGISTRATION NUMBER]
- Contact: privacy@sense-optimization.com
2. Data we collect
We collect the minimum data needed to provide and improve the Service. Here is a complete inventory:
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, hashed password, plan type | You, at signup |
| Payment data | Billing address, last 4 digits of card, transaction ID. Full card numbers are handled by Stripe — we never see or store them. | Stripe |
| Technical data | IP address, browser type, OS, device identifier, timestamps | Automatic, when you use the Service |
| Telemetry (optional) | Anonymous hardware specs, feature usage statistics, crash reports | Software, only if you opt in |
| Support correspondence | Messages you send us, attachments | You, when you contact support |
We do not collect: passwords from other services, browsing history outside our site, contents of your files, or biometric data.
3. How we use your data
We use personal data to:
- Create and manage your account
- Process payments, issue invoices, and prevent fraud
- Deliver the Service and provide customer support
- Send service-related communications (license activation, security alerts, policy updates)
- Improve reliability and performance through anonymous telemetry (opt-in only)
- Comply with legal obligations (tax records, responses to lawful requests)
We do not sell your personal data to third parties, and we do not use it for advertising or profiling unrelated to the Service.
4. Legal basis for processing (GDPR)
If you are located in the European Economic Area, UK, or Switzerland, we rely on the following legal bases under the GDPR:
- Contract performance — to deliver the Service you purchased (Art. 6(1)(b))
- Legal obligation — for tax, accounting, and regulatory compliance (Art. 6(1)(c))
- Legitimate interests — to secure the Service, prevent fraud, and improve product quality (Art. 6(1)(f))
- Consent — for optional telemetry and non-essential cookies, which you can withdraw at any time (Art. 6(1)(a))
5. Sharing with third parties
We share personal data only with trusted service providers who process it on our behalf under contractual obligations of confidentiality and security (Data Processing Agreements). Current sub-processors:
- Stripe, Inc. — payment processing (privacy policy)
- [HOSTING PROVIDER — e.g., AWS / Hetzner / OVH] — infrastructure hosting
- [EMAIL PROVIDER — e.g., Postmark / SendGrid] — transactional email delivery
- [ANALYTICS PROVIDER — e.g., Plausible / none] — privacy-respecting usage analytics
We may also disclose data if required by law, to enforce our Terms, or to protect the rights, safety, or property of Sense-Optimization, our users, or the public.
6. Data retention
We keep personal data only as long as necessary:
- Account data: while your account is active, plus 30 days after deletion
- Billing records: 7 years, as required by tax law
- Support tickets: 2 years after resolution
- Telemetry data: aggregated and anonymized after 90 days
- Server logs: 30 days
7. Security
We protect your data with industry-standard measures: TLS 1.2+ for data in transit, encryption at rest for sensitive fields, hashed and salted passwords (bcrypt), principle of least privilege for internal access, audit logs, and regular security reviews.
No system is perfectly secure. If we become aware of a personal data breach likely to result in a risk to your rights, we will notify affected users and the competent authority within 72 hours, as required by applicable law.
8. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA, and similar laws), you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectify — correct inaccurate or incomplete data
- Erase — request deletion of your data ("right to be forgotten")
- Restrict — limit how we process your data
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — at any time, where processing is based on consent
- Lodge a complaint — with your local data protection authority
To exercise any of these rights, email privacy@sense-optimization.com. We respond within 30 days and may request identity verification for security.
California residents: under the CCPA, you have additional rights including the right to know and the right to non-discrimination for exercising your rights. We do not sell personal information as defined by the CCPA.
9. Cookies & similar technologies
We use a minimal set of cookies:
- Essential cookies — required for login and security (cannot be disabled)
- Preference cookies — remember your settings (theme, language)
- Analytics cookies — optional, anonymous usage measurement (only with consent)
You can manage cookie preferences through the cookie banner on first visit, or in your browser settings at any time.
10. International data transfers
Your data may be transferred to and processed in countries other than your own, including the United States. When we do so, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and additional technical measures to ensure an equivalent level of protection.
11. Children's privacy
The Service is not intended for persons under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to registered users and/or by prominent notice on our website at least 14 days before they take effect. We encourage you to review this page periodically.
13. Contact & Data Protection Officer
For any privacy-related question or request:
- Email: privacy@sense-optimization.com
- Postal: [DPO / PRIVACY CONTACT NAME], [REGISTERED COMPANY ADDRESS]
- EU representative (if applicable): [NAME & ADDRESS, per GDPR Art. 27]
Template notice. This document is a starting template compliant with common GDPR/CCPA requirements. Replace bracketed placeholders with your actual details and have a qualified attorney review the final version for your specific operations.