Privacy Policy
1. Introduction, Scope & Data Roles
This Privacy Policy explains how SiteMind ("SiteMind", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit our website (https://sitemind.tech), register for an account, access our web applications, or interact with our embeddable chat widgets.
Under global data protection laws (including the EU General Data Protection Regulation / GDPR, UK GDPR, and the California Consumer Privacy Act / CCPA as amended by the CPRA), SiteMind acts in two distinct capacities:
A. SiteMind as a Data Controller
We act as a Data Controller for personal data concerning our direct customers, account holders, partners, and website visitors. This includes your name, email address, password hash, billing transaction metadata, IP address, and direct communications with our team.
B. SiteMind as a Data Processor / Service Provider
We act as a Data Processor (or "Service Provider") when processing data on behalf of our business customers. This includes crawled website text, uploaded documents (PDF, DOCX, CSV), end-user chat conversations, visitor lead captures, and customer-configured webhook triggers. For this data, the customer is the Data Controller, and our processing is strictly governed by our Data Processing Agreement (DPA).
2. Information We Collect
A. Information You Provide Directly
Account Credentials: Name, email address, workspace name, profile image, and cryptographic password hashes (bcrypt). For Google Sign-In, we collect your verified email, display name, and Google subject identifier.
Customer Content & Knowledge Base: Website URLs, crawled HTML text, uploaded files (PDFs, Word documents, text files), FAQs, and connected OAuth cloud data (Notion, Google Drive, GitHub, Confluence, Dropbox) submitted to train your AI assistant.
Lead Capture & Contact Forms: Names, email addresses, phone numbers, and optional inquiry notes submitted by visitors through the widget on customer websites.
Support & Communications: Messages, attachments, and feedback submitted via support tickets or email ([email protected]).
B. Information Collected Automatically
Chat Transcripts & Telemetry: Visitor queries, AI-generated answers, response latency, token consumption, thumbs up/down ratings, and optional user feedback comments.
Device & Terminal Identifiers: IP address, browser type, operating system, device cookie tokens (sm_device), referral attribution tokens (sm_ref), and persistent visitor identifiers (sitemind_visitor_id stored in browser localStorage).
Usage & Diagnostic Telemetry: Page views, interaction timestamps, referral URLs, and error diagnostic traces collected via privacy-conscious analytics tools.
Voice Audio Processing: When a visitor uses the optional widget voice input, audio is transcribed in real-time by the visitor’s browser Web Speech API. SiteMind receives and processes only the resulting text transcript.
3. Legal Bases for Processing (GDPR / UK GDPR)
If you reside in the European Economic Area (EEA) or United Kingdom (UK), we process your personal data only under valid legal grounds as established by Article 6 of the GDPR:
1. Contractual Necessity (Art. 6(1)(b)): Processing required to create and maintain your account, deliver AI indexing and chat streaming, process subscriptions via Polar.sh, and provide technical support.
2. Legitimate Interests (Art. 6(1)(f)): Processing required to secure our infrastructure against DDoS and unauthorized crawling, prevent prompt-injection attacks, detect fraud, and maintain operational stability, where our interests are not overridden by your fundamental rights.
3. Compliance with Legal Obligations (Art. 6(1)(c)): Processing required to satisfy tax, accounting, anti-fraud, and statutory reporting obligations.
4. Consent (Art. 6(1)(a)): Where you have provided affirmative consent, such as opting into non-essential analytics cookies or marketing communications.
4. How We Use Your Information
We use the collected information solely for legitimate business and operational purposes:
• Delivering the SiteMind Platform: Crawling website documentation, computing vector embeddings, performing Reciprocal Rank Fusion (RRF) hybrid search, and streaming grounded AI answers.
• Billing & Subscription Management: Facilitating secure checkout, renewal notices, and invoice generation through our Merchant of Record partner, Polar Software Inc.
• Security & Multi-Tenant Isolation: Enforcing strict per-workspace database row scoping, authenticating API tokens, and blocking malicious request patterns.
• Customer Service & Communication: Responding to support inquiries, notifying you of system maintenance, and sending transactional verification emails.
5. AI Models, Grounding & Zero-Training Guarantees
SiteMind is engineered on strict grounding and data-privacy invariants:
• Zero Model Training: We do not use your private website documentation, uploaded files, or visitor chat transcripts to train, retrain, or improve foundational commercial AI models.
• Strict Grounded RAG: Assistant responses are generated by passing retrieved context chunks inside structured, delimited security fences. The model is strictly instructed to answer only from your provided sources and refuse outside speculation.
• Enterprise Cloud Processing: Model inferences and text embeddings are executed via enterprise Google Cloud / Gemini API endpoints under commercial service terms that prohibit provider model training on customer inputs.
7. Subprocessors & International Data Transfers
SiteMind partners with trusted third-party infrastructure providers ("Subprocessors") to deliver cloud compute, database hosting, vector search, email delivery, and error diagnostics.
Our core infrastructure includes enterprise-grade managed database hosting with pgvector indexing (EU/US regions), cloud compute infrastructure, global edge CDN and encrypted document storage, AI inference processors (zero model training), PCI-DSS compliant billing providers, and transactional email infrastructure.
When data is transferred across international borders, SiteMind ensures appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs Module 2 & 3) under Commission Implementing Decision (EU) 2021/914 and the UK International Data Transfer Addendum.
A complete list of our authorized subprocessors is available at /subprocessors.
8. Data Retention & Deletion
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy or satisfy legal, accounting, and reporting obligations.
• Active Accounts: Knowledge base chunks, vector embeddings, and conversation histories are retained while your workspace remains active.
• Workspace Deletion: When you delete a website or workspace from your dashboard, access is immediately revoked and all associated data, documents, chunks, vectors, and conversation records are queued for permanent deletion within 30 days.
• Transaction Records: Financial transaction logs are retained for statutory tax and audit compliance periods required by law.
9. Your Data Protection Rights
Regardless of your geographic location, SiteMind recognizes and respects your statutory data protection rights. Under applicable laws (including GDPR, UK GDPR, and CCPA/CPRA), you have the right to:
• Right of Access (Art. 15 GDPR / CCPA): Request confirmation of whether we process your data and receive a copy of your personal data.
• Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data.
• Right to Erasure / Deletion (Art. 17 GDPR / CCPA): Request deletion of your personal data, subject to legal retention obligations.
• Right to Restrict Processing (Art. 18 GDPR): Request that we limit the processing of your data under certain conditions.
• Right to Data Portability (Art. 20 GDPR): Request an export of your personal data in a structured, commonly used, machine-readable format.
• Right to Object (Art. 21 GDPR): Object at any time to the processing of your personal data based on legitimate interests.
• Right to Withdraw Consent (Art. 7(3) GDPR): Withdraw consent at any time where processing is based on consent, without affecting past lawful processing.
• Right to Non-Discrimination (CCPA): Exercise any privacy right without penalty, price discrimination, or reduced service quality.
To exercise any of these rights, contact us at [email protected]. We respond to all verifiable requests within 30 days (or within 45 days for complex CCPA requests).
10. California Privacy Rights (CCPA / CPRA Notice)
This section provides additional disclosures required under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA").
In the preceding 12 months, SiteMind has collected the following categories of personal information for business purposes: Identifiers (name, email, IP address), Commercial Information (subscription history), Internet/Network Activity (browsing telemetry, widget interactions), and Audio Information (transcribed speech-to-text text).
Notice of Non-Sale and Non-Sharing: SiteMind DOES NOT SELL your personal information and DOES NOT SHARE your personal information for cross-context behavioral advertising.
We do not use or disclose Sensitive Personal Information for purposes other than performing the services reasonably expected by an average consumer.
11. Technical & Organizational Security Measures
We employ rigorous technical, administrative, and organizational safeguards designed to protect personal data from unauthorized access, loss, or alteration:
• Cryptographic Security: All data in transit is encrypted using modern TLS 1.3/1.2 protocols with strict SSL mode. Connected integration tokens (Shopify, Notion, Google Drive) are encrypted at rest using AES-256-GCM authenticated encryption.
• Tenant Row Scoping: Database queries strictly enforce per-workspace boundary checks. Vector similarity searches are partitioned and filtered by workspace ID.
• Prompt Security: Untrusted third-party website content is passed in fenced data turns with tag-sanitization to prevent prompt-injection attacks.
12. Children’s Privacy
SiteMind is a business-to-business (B2B) platform intended solely for commercial organizations and adult professionals. We do not knowingly solicit, collect, or process personal data from individuals under the age of 16. If we become aware that a child under 16 has provided us with personal data, we will immediately delete such information.
13. Contact Information & Supervisory Authority
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our privacy team:
Email: [email protected]
General Support: [email protected]
Website: https://sitemind.tech
If you are located in the European Union or United Kingdom and believe our processing violates applicable data protection laws, you have the statutory right to lodge a complaint with your local Data Protection Supervisory Authority (such as the UK Information Commissioner’s Office / ICO at https://ico.org.uk or your national EU Data Protection Authority).
Related Governance Resources
Review our comprehensive commercial contracts and security schedules: