Privacy policy
Sayaa provides a runtime assurance platform for regulated financial institutions. This policy explains what information we collect, how we use it, and the choices available to you.
Sayaa runs inside our customers' own environments, and nothing comes back to us.
The prompts the platform inspects, the sensitive data it detects, the enforcement decisions it makes and the audit records it produces all stay inside the customer institution's infrastructure. The deployment sends us no telemetry, no usage metrics, no crash reports and no license callbacks. We hold none of it, and we could not access it if we wanted to.
The only personal information we hold is what you give us directly when you contact us, and basic technical data our website host records when you visit.
That is the whole policy in three paragraphs. The rest sets out the detail.
Information We Collect
When you contact us. Name, work email address, job title, institution and whatever you choose to include in a demo request, contact form or email to us.
When you visit our website. Our hosting provider records standard server information including IP address, browser and device type, and pages requested. We do not run website analytics, and we do not use advertising or behavioral tracking of any kind.
When we work together. For customers and design partners, we hold business contact details for the people we deal with, and records of our correspondence and support requests.
That is the complete list. We do not collect sensitive personal information about you, and we do not build profiles.
What Stays Inside the Platform
Because Sayaa is deployed in the customer institution's own environment, everything the platform processes in normal operation remains there:
• Prompt and response content inspected to apply the institution's policies
• Detection results and confidence scores
• Enforcement records showing which policy applied and what action was taken
• Audit logs, approvals and configuration history
• Identifiers linking an interaction to a user, department, AI system or platform
The customer institution controls all of it, in infrastructure it operates. Retention, access and disclosure follow that institution's own policies and regulatory obligations.
Three things follow from this, and each matters.
We receive no telemetry. The deployment does not phone home for any purpose. There is no licence check, no version ping, no crash reporting and no usage measurement flowing back to Sayaa.
We cannot access customer environments. Our engineers hold no credentials, no VPN access and no administrative route into a customer deployment. If something needs investigating, the institution extracts and sends us the logs or diagnostic output it chooses to share. Where that material contains personal data, we use it only to resolve the issue and delete it when the matter closes.
We do not train on customer content. Prompt content, detection results and enforcement records are never used to train or improve any Sayaa or third party model. This is straightforward for us to commit to, because we never have the data.
We also do not operate a hosted demo or sandbox environment. Demonstrations run on customer infrastructure or on our own instance, so nothing you see in a demo involves us processing your data.
How We Use Information
We use the information we hold to:
• Respond to enquiries and provide support
• Administer customer and design partner relationships
• Communicate about service changes, security matters and availability
• Operate and secure our website and business systems
• Detect and prevent fraud, abuse and unauthorized access
• Meet our legal, regulatory and contractual obligations
We do not sell or share personal information. Under the California Consumer Privacy Act as amended by the CPRA, we do not sell personal information and do not share it for cross context behavioral advertising. We have not done so in the preceding twelve months, and we have no plans to.
Your Privacy Rights
If you are in the United States. Depending on your state, you may have the right to know what personal information we hold and how we use it, to access or receive a copy of it, to correct inaccuracies, to request deletion, and not to be discriminated against for exercising these rights. We do not sell or share personal information, so there is no opt out to exercise, though you are welcome to contact us to confirm that.
If you are in the EU, UK or another GDPR jurisdiction. You may also have the right to restrict or object to processing, to receive your data in a portable format, to withdraw consent where processing relies on it, and to complain to your supervisory authority. Our legal bases are performance of a contract, legitimate interests in operating and securing a business service, consent where you have given it, and compliance with legal obligations.
We verify identity before responding and reply within the period applicable law requires. You may use an authorized agent where your local law allows.
If your data was processed inside a customer institution's deployment, we cannot act on your request, because we do not hold that data. We will tell you promptly so you can approach the institution directly.
International Transfers
Sayaa is a United States company and our business systems operate from the United States. If you contact us from outside the United States, the information you send will be processed there. Where personal data reaches us from the EU or UK, we rely on Standard Contractual Clauses or another recognised safeguard.
Customer platform data is never transferred internationally by Sayaa, because it never reaches us.
Cookies
We use only the essential cookies needed for our website to function. We do not run analytics cookies, advertising cookies or any cross context tracking. You can manage cookies through your browser settings, and we honour Global Privacy Control signals where your browser sends them.
Security
We protect information using controls appropriate to a company serving regulated financial institutions.
In our own systems:
• Encryption in transit using TLS, and encryption at rest for stored data
• Role based access control with permissions scoped to each role
• Periodic internal security review
• Internal access controls and staff confidentiality obligations
In the platform, operating inside the customer's environment:
• Two eyes approval, so the person who authors a policy, detection rule or configuration change cannot be the person who activates it
• Cryptographic audit chaining using SHA-256, so altering an enforcement record breaks the visible integrity chain
• Authenticated sessions with token expiry and re authentication
• Role based access control across seven default roles
No system is perfectly secure. Where a breach affecting personal information occurs, we will notify affected individuals and the relevant authorities within the timeframes required by applicable state and federal law.
Because the platform runs inside the customer's environment and sends us nothing, a security incident affecting Sayaa's own systems cannot expose customer platform data.
Retention
We keep personal information only as long as we need it.
• Enquiry and contact records: 24 months from last contact
• Customer and design partner records: for the duration of the relationship.
• Support diagnostic material: deleted once the issue is resolved
• Website server logs: 90 days
Longer retention applies only where required by law or an ongoing legal claim.
Children
Sayaa is a business platform sold to financial institutions. It is not directed at anyone under 18, and we do not knowingly collect their information.
Changes to This Policy
We update this policy when our practices or legal obligations change. The date at the top shows the last revision. For material changes we post notice on this page and tell customers and design partners directly.
Contact
Questions, requests or complaints:
Email: discover@sayaa.ai
Privacy contact: Privacy team


