Brightboard AI Ltd, trading as Sentvia
Company number 16832757 · The Screening House, Cwm Cynon Business Park, Mountain Ash, United Kingdom, CF45 4ER · help@brightboardai.com
01
Who we are and when this policy applies
Brightboard AI Ltd (company number 16832757), trading as Sentvia ("Sentvia", "we", "us" or "our"), provides communication infrastructure that businesses and developers use to enable software and AI agents to send, receive and manage communications.
This policy explains how we handle personal data when you visit our website, create or administer an account, use our services, contact support, or otherwise interact with us.
For account, billing, website, security, marketing and support data, Brightboard AI Ltd is generally the controller. When a customer uses Sentvia to process email content, recipient details or other communications on its own behalf, the customer is generally the controller and we act as its processor. Questions about data in a customer's Sentvia account should normally be directed to that customer first.
02
Personal data we collect
Depending on how you use Sentvia, we may collect or process:
- Account and business data: name, work email, company, role, login and account administration information.
- Billing data: plan, transaction, invoice and payment status information. Payment card details are handled by Stripe rather than stored by us in full.
- Customer communications data: sender and recipient addresses, message content, subject lines, headers, attachments, delivery events, replies, threading and related metadata.
- Technical and usage data: IP address, browser or device information, API requests, timestamps, logs, identifiers, webhook events, product usage and diagnostic information.
- Security and abuse data: signals used to prevent spam, fraud, misuse, malicious activity and threats to platform deliverability.
- Support and marketing data: enquiries, support conversations, feedback and communication preferences.
We receive data directly from you, from authorised users of your organisation, through use of the service, from communications processed at a customer's instruction, and from service providers that support our operations.
03
How and why we use personal data
We process personal data where necessary to:
- provide, operate, maintain and support Sentvia;
- create and administer accounts, authenticate users and manage subscriptions;
- route, deliver, receive, store and search communications as instructed by customers;
- monitor performance, troubleshoot problems and improve reliability and product functionality;
- detect and prevent spam, abuse, fraud, security incidents and unlawful use;
- process payments, maintain financial records and enforce our agreements;
- respond to enquiries and provide service communications;
- send relevant product or marketing communications where permitted, with an option to opt out; and
- comply with legal obligations and protect our rights, users and the public.
Our legal bases under UK data protection law include performance of a contract, compliance with legal obligations, our legitimate interests in operating and securing the service and developing our business, and consent where the law requires it. Where we act as a processor, we process personal data on the documented instructions of the relevant customer.
05
International transfers
Some providers or their systems may be located outside the United Kingdom. Where personal data is transferred internationally, we use a lawful transfer mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with appropriate technical and organisational safeguards.
06
How long we keep data
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including to provide the service, follow customer instructions, resolve disputes, enforce agreements and meet legal, accounting or security requirements.
Retention depends on the data and context. Account data is generally kept while an account is active and for a reasonable period afterwards. Customer communications data is retained according to the service configuration, customer instructions and contractual requirements. Financial records may be retained for the period required by UK tax and company law, typically up to six years after the relevant financial year. Security logs and backups may persist for limited periods before deletion or overwriting.
07
Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or disclosure. These include access controls, monitoring, infrastructure safeguards and measures to identify abusive or malicious sending. No system is completely secure, and you are responsible for protecting your credentials, API keys and account access.
09
Your UK data protection rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict personal data; object to processing; receive portable data; and withdraw consent at any time where processing relies on consent. You may also object to direct marketing at any time.
To exercise a right, email help@brightboardai.com. We may need to verify your identity. If Sentvia processes the data only for one of our customers, we may refer the request to that customer or assist it in responding.
You can complain to the UK Information Commissioner's Office at ico.org.uk, although we would appreciate the opportunity to address your concern first.
10
Changes and contact
We may update this policy to reflect changes to Sentvia, our providers or the law. We will publish the revised version here and update the effective date. If a change materially affects your rights, we will take reasonable steps to provide additional notice.
Questions about this policy or our data practices can be sent to help@brightboardai.com or by post to Brightboard AI Ltd, The Screening House, Cwm Cynon Business Park, Mountain Ash, United Kingdom, CF45 4ER.