Privacy & data
The privacy portal is where you exercise your own GDPR rights over the personal data Sencai holds about you, and - on Enterprise - where your organization maintains its own processing register. This page covers self-service actions available to any user; it’s separate from your organization’s Data Processing Agreement, which covers the contractual relationship between your organization and Sencai as a processor.
Find it at Legal → Privacy & Data in the app (/gravity/settings/privacy).
What personal data Sencai holds about you
Section titled “What personal data Sencai holds about you”The data these actions operate on is what Sencai holds about you as a user - your profile (name, email, and similar account fields), your organization memberships, your cookie consent record, and entries in Sencai’s audit log attributed to your own account. It does not include the content of the cloud infrastructure your organization manages - that belongs to your organization, not to your individual GDPR rights as a user.
Downloading your data
Section titled “Downloading your data”Three related download options are on this page:
- Download My Data - a machine-readable bundle (JSON or CSV) covering your profile, organization memberships, and your own recent audit log entries. Encrypted credentials are excluded.
- GDPR Art.20 - Data Portability - a similar export (JSON or XML) covering profile, organization memberships, audit history, and consent records, framed specifically around the right to portability.
- Request Email Export - requests the same kind of archive delivered to your registered email address instead of downloaded directly in the browser.
These three options overlap in what they contain; use whichever format is more convenient for your purposes.
Records of Processing Activities (Enterprise)
Section titled “Records of Processing Activities (Enterprise)”For organizations that need to maintain their own GDPR Art.30 register, RoPA management
(/gravity/settings/privacy/ropa) lets you record processing activities directly in Sencai -
data category, legal basis, purpose, processor, retention period, and (if applicable)
cross-border transfer safeguards. You can create, edit, and delete entries, filter the list by
data category or legal basis, and export the whole register as CSV. Each entry shows whether
it’s complete (all required fields filled) or still incomplete.
Data subject access and erasure requests
Section titled “Data subject access and erasure requests”Right to erasure (GDPR Art.17) is the “Request data deletion” action at the bottom of this page. It’s self-scoped to your own account - there’s no way to request erasure of anyone else’s account from here, and no organization admin action does this on someone else’s behalf either.
When you confirm the request, Sencai performs the following immediately:
- Your account is disabled and you’re signed out - you can’t log back in
- Your profile fields (name, email, and related contact fields) are anonymized
- Your cookie consent record is anonymized
- You’re removed from every organization you’re a member of
- The request itself is logged
Sencai’s audit log is append-only and immutable by design - entries already recorded against your account before the erasure request are not retroactively edited, since altering historical audit entries would undermine the same tamper-evidence property that makes the audit log useful as compliance evidence in the first place. Your account being anonymized means future activity can no longer be tied to your identifying details, but it doesn’t rewrite the historical record.
Your underlying account record is scheduled for permanent deletion 90 days after the request - a cooling-off window before the physical record is gone for good. Other GDPR rights (access, rectification, restriction) or anything not covered by this self-service flow can be raised directly with Sencai’s Data Protection Officer at privacy@sencai.space; the same address handles requests within one month, per the response commitment on Sencai’s own privacy policy.
Cookie consent
Section titled “Cookie consent”The Cookie Preferences section lets you toggle Analytics and Marketing cookies independently (Necessary cookies, required for authentication and session security, can’t be disabled) and Withdraw all consent in one action, which disables both optional categories and clears your consent record.
Exporting your organization’s data
Section titled “Exporting your organization’s data”Separately from your own personal GDPR export above, Data Export (Intelligence →
Data Export, /gravity/analytics/export) is a broader, BI-oriented export of your
organization’s own operational data - audit logs, cost records, and cloud instance data -
suitable for loading into a data warehouse (BigQuery, Snowflake, Redshift) or any
NDJSON-compatible pipeline. Choose a date range, the tables to include, and JSON or NDJSON
format; the export is capped at 10,000 rows per table. This is an operational/BI tool, not a
GDPR mechanism - for your own personal data, use the downloads described above instead.
What deleting an organization does
Section titled “What deleting an organization does”Deleting an organization (from its own Settings) is a distinct, separate action from personal account erasure above, and it requires the Owner role - the only role that can. It removes the organization from the platform, but it does not, by itself, erase the personal GDPR data of individual members - each member controls their own account erasure independently via this page.
What’s next
Section titled “What’s next”- Agreements - your organization’s DPA and MSA, a separate mechanism from personal data rights
- Compliance overview - how privacy fits into the rest of the compliance area
- Getting started: roles - who can delete an organization
- Identity → Account security - securing the account whose data this page manages