This Privacy Policy explains how TokiSpace Inc ("Sendara", "we", "us") handles personal data in connection with the Sendara email-sending API, dashboard, webmail, and websites at sendara.dev, app.sendara.dev, api.sendara.dev, and mail.sendara.dev (collectively, the "Service"). It applies to personal data we handle as a controller. Where we process recipient personal data on behalf of our customers, we act as a processor (see Controller vs. processor below).
1. Controller vs. processor
We handle two very different categories of personal data, and our role differs for each:
- Account data (we are the controller). Data about our customers and the people who administer accounts. Examples are your name, email address, hashed password, billing identifiers, and usage logs. This policy governs how we use that data.
- Recipient data (we are the processor). When you send email through Sendara, you provide recipient email addresses, contact attributes, message content, and the resulting send and event logs. We process that data only on your instructions to deliver the Service. You are the controller of that data; we are your processor. Your handling of recipient data is governed by your own privacy notice and our Data Processing Addendum, not this policy.
2. Personal data we collect (as controller)
- Account and profile data: name, email address, hashed password, organization details, and API keys you generate.
- Billing data: plan, subscription status, and billing identifiers. Payment-card details are collected and stored by our merchant of record, Polar. We do not store full card numbers.
- Usage and log data: API requests, send and delivery event logs, IP addresses, timestamps, device/browser metadata, and diagnostic logs used for security, billing, and support.
- Support and communications: messages you send us and our responses.
- Website data: essential cookies and limited analytics needed to operate the site.
3. How we use personal data
- to provide, operate, secure, and improve the Service;
- to authenticate you, manage your account, and process subscriptions and billing (through our merchant of record);
- to monitor for abuse, enforce our acceptable-use rules, and protect platform deliverability;
- to provide support and respond to your requests;
- to send service and transactional messages, and (where permitted) product updates you can opt out of; and
- to comply with legal obligations and enforce our agreements.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service); our legitimate interests (to secure, improve, and operate the Service and prevent abuse); compliance with legal obligations; and consent where required (for example, non-essential marketing). You may withdraw consent at any time without affecting prior processing.
5. Subprocessors and sharing
We do not sell personal data. We share it with vetted service providers (subprocessors) who process it on our behalf under contract, and with authorities where legally required. Our current subprocessors are:
- Amazon Web Services (AWS): email delivery via Amazon SES, and core infrastructure (Aurora/RDS, ElastiCache, S3, App Runner, Lambda), hosted in the
us-east-1region. - AWS Bedrock: the AI features described in section 5a. Bedrock runs the model inside AWS. Under our agreement with AWS, AWS does not share prompts or outputs with the provider of the model and does not use them to train a model. We rely on that commitment; we cannot independently verify it.
- Polar (Polar Software Inc.): billing, checkout, and tax as our merchant of record.
- Cloudflare: website/app hosting and DNS.
Open tracking and click tracking are enabled on our Amazon SES configuration set. Amazon SES adds a tracking pixel to a message and rewrites a tracked link to the awstrack.me domain, which Amazon operates. A recipient who opens a message or selects a tracked link therefore sends their IP address and user agent to Amazon. A branded tracking domain is not available.
5a. AI features
Two features send data to AWS Bedrock. They differ, and we describe them separately so that you know which applies to you.
Sendara Mail AI is opt-in. You turn it on for an account. Until you do, no mailbox content reaches Bedrock.
The support assistant runs whenever you open the support chat. There is no separate setting for it. Two different things reach Bedrock, and they are protected differently.
What you type is sent as written. Every message you send in the support chat goes to Bedrock as you wrote it. We do not filter, mask, or redact it. Please do not paste a recipient address, a message body, an API key, or anything else you would not want a model and a member of our staff to read.
What the assistant looks up is filtered. The assistant can read your own account records to answer you, through a fixed set of lookups:
- It receives message metadata: the message id, the status, the timestamps, the delivery events, and the subject line.
- It never receives the body of a message, and it never receives an attachment. The lookup returns a fixed set of fields, and the body is not one of them.
- A message lookup returns no recipient address at all. Where a record is about an address, such as your suppression list or your test recipients, the assistant receives it masked, as
a***@example.com. - Free-text fields in those records can still mention an address, so we run a removal pass over them before the assistant sees them: the subject line, the reason stored against a suppression, and the diagnostic text a receiving mail server returns. A subject such as
Password reset for [email protected]reaches the assistant asPassword reset for [address redacted]. That pass is deliberately broad, and it will sometimes redact text that was not an address. It is a filter on our records, not a guarantee about text you supply yourself.
The assistant reads. It cannot send a message, change a setting, or delete a record.
People at Sendara can read your support conversations. Support conversations are stored against your account. When the assistant cannot answer confidently, it hands the conversation to a person on the Sendara team, who reads it and replies in the same thread. Sendara staff can also open a support conversation from our internal console to investigate or answer it, including one that was never handed over. Staff access is limited to authorized personnel and is logged.
For recipient data we process on your behalf, the authoritative, version-tracked subprocessor list and our change-notification commitments are in the Data Processing Addendum.
6. International data transfers
We and our subprocessors operate primarily in the United States (AWS us-east-1). Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), as referenced in our Data Processing Addendum.
7. Data retention
We keep account data for as long as your account is active and as needed to provide the Service, then for a limited period afterward to meet legal, tax, accounting, and dispute-resolution obligations. Send and event logs are retained for operational, deliverability, and abuse-prevention purposes for as long as your account is active. We do not operate a fixed-period deletion or anonymization schedule for those logs. Support conversations, including the messages you type into the support chat and the assistant's replies, are kept on the same basis: for as long as your account is active, with no fixed-period deletion schedule. Recipient data processed on your behalf is retained and deleted as set out in the Data Processing Addendum and on your instruction.
8. Security
We use technical and organizational measures designed to protect personal data, including TLS on public network connections, encryption at rest for stored data, hashing of passwords, scoped API keys, network controls, least- privilege access, and logging and monitoring. No method of transmission or storage is completely secure, but we work to protect your data and to notify affected parties of a security breach as required by law.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict our processing of your personal data, to object to certain processing, and to withdraw consent.
EEA/UK (GDPR, UK GDPR): you have the rights above and the right to lodge a complaint with your supervisory authority.
California (CCPA/CPRA):you have the right to know what personal information we collect and how we use and disclose it, to request access and deletion, to correct inaccurate information, and to opt out of any "sale" or "sharing" of personal information. We do not sell personal information. We will not discriminate against you for exercising these rights.
To exercise your rights, email [email protected]. If your request concerns recipient data we process on a customer's behalf, we will refer you to that customer (the controller). We will verify your request and respond within the timeframes required by law.
10. Children
The Service is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice.
12. Contact us
For privacy questions or to exercise your rights, contact us at [email protected]. Our Data Protection Officer (or privacy contact) can be reached at [email protected]. Postal mail: TokiSpace Inc, Mile 11, Bort Street 25, Accra, Ghana.