Sorsend Privacy Policy
At Sorsend, we take your privacy seriously and are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This Privacy Policy explains how we collect, use, store, share, and safeguard your personal data when you use our services as a natural person (individual), not acting on behalf of an organisation.
1. Who We Are – Data Controller
This Privacy Policy applies to Sorsend as the data controller for personal data processed in connection with the services we offer to individuals within the European Union.
Controller Contact Details:
- Name: Sortask GmbH
- Address: Münzgrabenstraße 44/12
- Postal code: 8010
- City: Graz
- Country: Austria
- E-Mail: office@Sorsend.com
2. Personal Data We Collect
We may collect and process the following categories of personal data:
- a. Identity and Contact Data
- Full name, email address
- Contact details you submit via contact forms or support requests
- b. User Content and Account Data
- Emails and task content you upload or sync with our platform
- Preferences, labels, and tags you apply
- c. Device and Technical Data
- Log data on your activity (e.g., access timestamps, clicked features)
- d. Usage and Interaction Data
- Interaction patterns with features and settings
- User behavior data for troubleshooting and optimization
- e. Third-party Integration Data
- Information retrieved from services you connect to Sorsend (e.g., Gmail, Outlook)
- f. Marketing and Communication Preferences
- Records of your communication choices (e.g., newsletter opt-ins)
3. How and Why We Use Your Personal Data
We process your personal data for the following purposes and under the respective lawful bases defined in Article 6 of the GDPR:
| Purpose | Legal Basis |
|---|---|
| To create and maintain your account and user profile | Performance of a contract (Art. 6(1)(b)) |
| To provide services (task categorization, email sorting, project features) | Performance of a contract (Art. 6(1)(b)) |
| To respond to support requests or inquiries | Legitimate interest or pre-contractual steps (Art. 6(1)(f) or Art. 6(1)(b)) |
| To send transactional notifications (e.g., service updates, security alerts) | Legitimate interest (Art. 6(1)(f)) |
| To send marketing communications (only with consent) | Consent (Art. 6(1)(a)) |
| To analyze service usage and improve performance | Legitimate interest (Art. 6(1)(f)) |
| To comply with legal obligations (e.g., tax, fraud prevention) | Legal obligation (Art. 6(1)(c)) |
5. Data Sharing and Transfers
We only share personal data with trusted third parties when necessary to provide the service or when required by law. These include:
- a. Sub-processors (Data Processors)
- Cloud service providers (e.g., AWS, Azure)
- Email delivery providers
- AI infrastructure providers
- Analytics and diagnostics tools (e.g., Google Analytics, Microsoft Clarity)
- b. Third-party Integrations
If this feature is available you may enable integrations with email services or productivity tools, we access only the data required for the feature and based on your instructions.
- c. Legal or Regulatory Authorities
If legally obliged, we may disclose your data to courts, law enforcement, or public authorities under Art. 6(1)(c) GDPR.
6. International Data Transfers
Your data may be transferred to countries outside the EU/EEA. In such cases, we rely on appropriate safeguards, such as:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Additional technical and contractual protections
7. Data Retention
- Active user data is retained for the duration of the account
- Upon account deletion, data is permanently removed within 30 days (unless otherwise required by law)
You may export or delete your data at any time through your account or by contacting us.
8. Security Measures
We implement technical and organizational measures under Art. 32 GDPR to protect your data, including:
- Encryption of data in transit and at rest
- Access controls and role-based authorization
- Intrusion detection and logging
- Secure development and deployment practices
- Incident response protocols
- Employee confidentiality agreements and training
9. Your Rights Under the GDPR
As a data subject, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR – 'right to be forgotten')
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time (Art. 7(3) GDPR)
- Right to lodge a complaint with your local Data Protection Authority (Art. 77 GDPR)
To exercise these rights, contact: office@Sorsend.com.
10. Automated Decision-Making and Profiling
We use AI to categorize emails and tasks automatically. However, no decisions with legal or similarly significant effects are made solely based on automated processing.
12. Children’s Data
Our services are not intended for users under the age of 16. If we learn we have processed data of a child under 16 without verified parental consent, we will delete that data promptly.
13. Responsible Use of AI and Protection of Your Data
Sorsend leverages artificial intelligence (AI) to enhance service capabilities, such as automated email categorization and task creation and prioritization. Our AI models are designed to improve productivity and support your user experience through contextual understanding and pattern recognition while respecting the principles set forth in the EU AI Act.
We are committed to the ethical and privacy-conscious use of AI and observe the following principles:
- We do not use your personal data to train our AI models. This means:
- Your emails, tasks, and metadata are not used to refine, retrain, or expand any machine learning model.
- We do not transfer your personal data into shared training environments.
- Our AI models are trained using synthetic or anonymized datasets that are independent of user content.
14. Updates to This Policy
We may update this Privacy Policy to reflect changes in legal, technical, or business developments. We will notify you via the platform or email if changes are material.