Legal Compliance

Privacy Policy

Last Updated: May 2026

1. Who We Are

This privacy policy sets out how Sanganix AI collects, uses, and protects your personal and corporate data through your use of our website (sanganixai.com) and when you engage our custom AI automation services, including deployments of Python applications, n8n workflows, and Agentic AI architectures.

Sanganix AI acts as the data controller and is responsible for your personal data.

2. Types of Personal and Corporate Data We Collect

We may collect, use, store, and transfer different kinds of data to architect and support your automations:

  • Identity Data: Name, username, role, and job function.
  • Contact Data: Work email address, phone number, and billing address.
  • Technical Integration Data: Internet protocol (IP) addresses, API tokens, webhook URLs, database credentials, and system architecture details required to deploy custom solutions on cloud environments (e.g., GCP, OCI).
  • Financial Data: Payment and billing information for service retainers and project invoices.
  • Usage Data: Information about how your deployed automations interact with third-party platforms (e.g., API call volumes, error logs, execution times).

3. Sources of Data Collection

We collect data through the following methods:

  • Information You Provide to Us: When you fill out our Discovery Questionnaire, sign a Statement of Work, or securely hand over API keys and environment variables for project development.
  • Information We Collect Automatically: Our custom scripts and n8n workflows may automatically log technical usage data, error reports, and system performance metrics to ensure 24/7 uptime of your automated processes.
  • Information from Third Parties: Data passed back from the external platforms we integrate with on your behalf (e.g., OpenAI, your CRM, or external databases).

4. Lawful Bases for Processing Personal Data

We process your data based on the following legal foundations:

  • Performance of a Contract: Processing data necessary to build, deploy, and maintain the custom AI agents and workflow orchestrations outlined in our Master Services Agreement (MSA).
  • Legitimate Interests: Analyzing system error logs and API volume to optimize cloud infrastructure, improve code performance, and secure your systems against malicious activity.
  • Legal Obligations: Retaining certain financial and technical records to comply with local regulatory and tax requirements.

5. Purposes of Processing Data

  • To provide our services: Architecting hybrid technical stacks (Python + n8n) and managing dedicated cloud server environments.
  • To ensure security: Implementing encryption and secure environment variables to protect the flow of data between your master CRM and third-party tools.
  • To provide ongoing maintenance: Handling standard API token expirations and monitoring systems for downtime.

6. Data Retention

We retain your personal and technical data only for as long as is necessary to fulfill the purposes for which it was collected. API keys and sensitive access credentials are kept active only for the duration of the contracted maintenance period.

Upon termination of our services, we will securely destroy or return all proprietary data, code blocks (excluding Sanganix AI retained IP), and environment variables, except where retention is required by law.

7. Automated Decision-Making and AI Agents

Certain core features of the services we build for you (such as Agentic AI workflows) incorporate automated decision-making processes. These custom agents perform tasks and generate outputs automatically based on the algorithmic logic we design and the data they access.

We ensure "Human-in-the-Loop" (HITL) fail-safes can be configured upon request to govern critical automated actions.

8. Your Data Protection Rights

Under applicable data protection laws, you have the right to:

  • Request Access: Obtain a copy of the data we hold about you or your systems.
  • Request Rectification: Correct any inaccurate or incomplete code or data configurations.
  • Request Erasure: Ask us to delete or remove data when there is no good reason for us to continue processing it.
  • Right to Object: Object to our processing of your data based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time where we rely on consent to process your data.

9. Contact Details

If you have any questions about this privacy policy, how we manage secure AI deployments, or want to exercise your legal rights, please contact us:

Questions about our privacy practices? Reach out to us at sanganixai@gmail.com or via our strategy sync booking to discuss our data governance framework.