Privacy
Privacy Policy
This policy explains what Sernixa collects, why it is used, when it is shared, how long it is kept, and the choices available to individuals.
Effective date: July 17, 2026
Last updated: July 17, 2026
1. Scope
This Privacy Policy applies when you visit Sernixa websites, create or use a hosted account or workspace, use Sernixa APIs, SDKs, command-line tools or local agents, connect an integration, communicate with us, or receive support. It covers personal information processed by Sernixa, Inc. ("Sernixa," "we," "us," or "our").
This policy does not govern a third-party service you connect to Sernixa or a customer-controlled deployment that does not send data to Sernixa. Those services and deployments have their own privacy terms.
2. When Sernixa Is a Controller or Processor
Sernixa acts as a controller (also called a business or data fiduciary in some laws) for website, account, billing, support, security, and service-analytics data when we determine why and how it is processed.
For personal data submitted by a customer through governance actions, evidence, audit records, integrations, or connected runtimes, Sernixa generally acts as the customer’s processor or service provider. The customer determines the purpose and instructions, handles notices and permissions for its data subjects, and is the first contact for requests about that Customer Data. A data processing agreement or Order Form may provide additional terms.
3. Information We Collect
- -Account and identity data: name, business email address, profile image, Google or other configured identity-provider identifiers and claims, sign-in status, and session identifiers.
- -Organization and access data: organization and team names, role, permissions, invitations, membership, administrator actions, plan, region, and workspace settings.
- -Governance and Customer Data: action metadata and content, prompts or model output a customer chooses to submit, policy inputs and results, risk levels, approvals and reviewer comments, delegation chains, audit events, evidence payloads, DLP findings, circuit-breaker events, and export records.
- -Agent, MCP, and discovery data: agent and machine identifiers, labels, versions, runtime and service metadata, tool or server names, endpoints, configuration observations, discovery candidates, enrollment state, sync status, and limited process, file, network, or eBPF observations enabled by the customer.
- -Integration and credential metadata: connected provider, workspace or channel identifiers, scopes, status, webhook or callback configuration, API-key identifier and prefix, signature or verification status, and token lifecycle events. Raw secrets are processed only as needed to establish or operate the connection.
- -Billing and transaction data: plan, price, currency, billing interval, region, subscription status, provider customer and subscription identifiers, invoice or payment status, and tax or business details. When hosted checkout is used, the payment processor—not Sernixa—receives full card or bank credentials.
- -Technical, usage, and security data: IP address, request date and time, requested URL, referrer, browser, operating system, device type, approximate country or region, SDK or agent version, service identity, diagnostics, error and availability events, request metadata, nonce or replay status, and security reason codes.
- -Communications: questions, feedback, support requests, call or meeting details, and other information you choose to send us.
Please do not submit personal data that is unnecessary for the governance purpose, or passwords, raw private keys, full payment-card data, government identifiers, health data, biometric identifiers, children’s data, or other highly sensitive data unless an applicable written agreement expressly supports that processing.
4. Sources of Information
- -Directly from you when you sign in, configure a workspace, choose a plan, contact us, or operate an SDK, API, or local agent.
- -From your organization, such as an administrator, inviter, reviewer, or connected runtime.
- -From identity, payment, collaboration, cloud, registry, and other providers you or your organization connect.
- -Automatically from browsers, devices, servers, SDKs, APIs, logs, and security controls when the Services are used.
- -From public sources when a feature imports public MCP registry, package, repository, or service metadata. Public-source provenance is retained where the feature supports it.
5. Why We Use Information and Our Legal Bases
- -Provide the Services and perform a contract: authenticate users, create workspaces, evaluate policies, route approvals, maintain integrations, show evidence, enforce entitlements, process payments, and provide support.
- -Follow customer instructions: process Customer Data as a processor or service provider for the customer’s configured governance purpose.
- -Protect legitimate interests: secure accounts and infrastructure, prevent fraud and abuse, diagnose faults, maintain availability, understand aggregate service use, and improve reliability, balanced against individual rights.
- -Comply with legal obligations: maintain required business and security records, respond to valid legal process, and enforce applicable rights and restrictions.
- -Use consent where required: establish an optional integration, send optional marketing, or perform another use for which applicable law requires consent. Consent may be withdrawn without affecting earlier lawful processing.
Where a law uses different terminology, we rely on the corresponding permitted basis, including consent, performance of a contract, compliance with law, or a permitted legitimate use. We do not process personal information for a new incompatible purpose without a valid legal basis and any required notice or consent.
6. AI, Model Output, and Governance Data
Sernixa may process raw or normalized model and tool output when a customer submits it for policy evaluation, Counterfactual Twin, Intervention Trace, approval review, evidence, or another enabled feature. The customer controls what is submitted and who may review it.
Sernixa does not use Customer content to train a general-purpose AI model unless that use is expressly disclosed and authorized in a separate written agreement. Customer-enabled third-party model providers may process data under the customer’s configuration and their own terms.
9. No Sale or Behavioral Advertising
Sernixa does not sell personal information for money and does not share personal information for cross-context behavioral advertising or targeted advertising as those terms are defined by applicable U.S. state privacy laws. We do not use sensitive personal information to infer characteristics about individuals. Because we do not conduct those activities, a sale or targeted-advertising opt-out is not currently necessary. If this changes, we will update this policy and honor applicable opt-out preference signals, including Global Privacy Control where required.
10. International Data Transfers
Sernixa and its providers may process information in countries other than the country where it was collected. Privacy protections may differ. Where required, we use a lawful transfer mechanism such as contractual protections, an adequacy decision, or another approved safeguard, and apply any applicable Indian transfer restriction or customer-agreed residency term. Contact us to request information about safeguards relevant to your data.
11. Data Retention
We keep personal information only for as long as reasonably necessary for the purpose described, the customer’s instructions and plan, security and audit integrity, dispute resolution, and legal obligations. The criteria below apply unless an Order Form, data processing agreement, legal hold, or law requires a different period:
- -Account, organization, and settings data: while the account or workspace is active, followed by a limited deletion and backup-rotation period.
- -Authentication sessions: up to 30 days in the standard hosted configuration, subject to earlier sign-out, revocation, or administrator action.
- -Governance, approval, audit, discovery, and evidence data: for the retention period associated with the customer plan or Order Form and as needed to preserve requested audit integrity. A separate security or legal record may be retained longer.
- -Integration configuration and credential metadata: while the integration is active and for the limited period needed to confirm disconnection, investigate abuse, or preserve an audit record. Disconnecting Sernixa does not automatically delete data held by the third-party provider.
- -Billing and transaction records: for the subscription and the additional period required for tax, accounting, fraud prevention, and dispute obligations.
- -Support communications: while the request is active and for a reasonable period afterward to document the resolution and improve support.
- -Security and diagnostic logs: for the period needed to detect, investigate, remediate, and prevent incidents, including any minimum period required by applicable law.
- -Vercel analytics: the daily visitor identifier is discarded after 24 hours; aggregate reporting availability depends on the Vercel plan and is generally 1 to 24 months.
Deletion may take additional time in encrypted backups, where data remains isolated until the backup is overwritten. We may retain de-identified information that is not reasonably capable of being linked to an individual. Customers control deletion of data that remains solely in their local or self-hosted environment.
12. Security and Incident Response
We use reasonable administrative, technical, and organizational measures designed to protect personal information. Depending on the feature and deployment, these include access controls, scoped roles and credentials, encryption in transit, protected secrets, signed request envelopes, replay controls, logging, and audit-integrity mechanisms.
No system is risk-free. Customers must secure their endpoints, accounts, networks, integrations, local agents, and exported data. If we confirm a personal-data breach, we will investigate, take reasonable mitigation steps, and notify affected customers, individuals, or authorities as required by applicable law and our contractual role.
13. Automated Decisions
Sernixa provides policy evaluation, risk classification, simulations, evidence, and approval routing. For Sernixa’s own purposes, we do not use personal information to make solely automated decisions that produce legal or similarly significant effects about an individual. Customers decide how to configure and use governance results and are responsible for required explanations, impact assessments, human review, and appeal rights for their own use cases.
14. Your Privacy Rights and Choices
Depending on where you live and subject to legal exceptions, you may ask to access, know about, correct, delete, or receive a portable copy of personal information; restrict or object to processing; withdraw consent; opt out of certain disclosures or automated decisions; appeal a denied request; nominate or authorize another person; and receive equal service without unlawful discrimination for exercising a right.
For account data controlled by Sernixa, send a request to contact@sernixa.com with the subject "Privacy Request." Include your account email, organization, country or state, the right requested, and enough detail to locate the data. Do not send identity documents unless we request a secure verification method. We may verify the request through the account, email, administrator, or other proportionate information and may need to confirm an authorized agent’s authority.
For Customer Data controlled by your employer or another Sernixa customer, contact that organization first. We will assist the customer as required by contract and law. You may withdraw consent using the same account or integration control used to grant it where available, or by contacting us. We will respond within the period required by applicable law and explain any denial and available appeal or complaint route.
15. Regional Notices
European Economic Area and United Kingdom. Section 5 identifies our legal bases. You may exercise the rights in section 14 and lodge a complaint with your local data-protection authority. Where legitimate interests apply, you may request information about the balancing considered. International transfers use the safeguards described in section 10.
India. Where the Digital Personal Data Protection Act and its rules apply, you may request access to processing information, correction, completion, updating or erasure, use the grievance process, withdraw consent, or nominate another person as provided by law. Send a grievance or rights request to contact@sernixa.com. We will publish or provide any additional mechanism required as relevant provisions take effect.
California and other U.S. states. In the preceding 12 months, Sernixa collected the categories in section 3 from the sources in section 4, used them for the purposes in section 5, and disclosed relevant categories for business purposes to the recipients in section 8. Sernixa did not sell or share them for cross-context behavioral advertising and has no actual knowledge that it sold or shared personal information of anyone under 16. Applicable residents may exercise the rights in section 14, including correction, deletion, access, portability, opt-out, or appeal rights available under their state law.
16. Children
The Services are intended for business users who are at least 18. Sernixa does not knowingly offer accounts to or collect personal information directly from children. Do not submit children’s personal information through the Services without a lawful basis, required parental authorization, and an applicable written agreement. If you believe a child’s information was submitted improperly, contact us so we can investigate and delete it where required.
17. Customer Privacy Responsibilities
- -Tell Authorized Users and other affected individuals how Customer uses Sernixa and identify Customer as the controller or data fiduciary where applicable.
- -Submit only data Customer is authorized to process and configure collection, approvals, integrations, access, and retention consistently with Customer’s notices and legal obligations.
- -Respond to rights requests for Customer Data and notify Sernixa when assistance is needed.
- -Avoid secrets and unnecessary sensitive data in prompts, policy context, evidence, logs, discovery labels, URLs, or support messages.
- -Review third-party integration settings and disconnect or revoke access in both Sernixa and the third-party service when appropriate.
18. Changes to This Policy
We may update this policy as the Services, providers, or legal requirements change. We will post the revised policy with a new last-updated date. If a change materially affects how we use personal information, we will provide additional notice through the Service or by email where required and seek consent where applicable law requires it.
19. Contact and Grievances
Sernixa, Inc. is the contact for this policy. Send privacy questions, rights requests, or grievances to contact@sernixa.com with the subject "Privacy Request" or "Privacy Grievance." Account and security support may be sent to support@sernixa.com. Include your account email, organization, location, and a clear description, but do not email passwords, raw API keys, payment-card data, or unnecessary identity documents.