CendriLog in
This document is provided for transparency and is not legal advice. Cendri is not a law firm; please have your own counsel review this policy before relying on it.
Legal

Privacy Policy

Last updated: July 13, 2026 · Version: 2026-07-13

1. Who We Are and How to Reach Us

This Privacy Policy explains how Cendri, Inc. ("Cendri," "we," "us," or "our") collects, uses, shares, and protects personal data when you use the Cendri platform (the "Service"). For the personal data of account holders and the people they invite, Cendri acts as the controller. When we process content and deal-room data on behalf of a customer organization under our agreement with it, we act as a processor for that organization. In either role, we rely on the sub-processors described below.

For any privacy question or request, contact us at privacy@cendri.com.

2. What We Collect

Account information — your name, email address, a hashed password (we never store passwords in plaintext), and your role (Seller/Delivering Party or Buyer/Receiving Party). Deal metadata — deal-room names, statuses, invitations, and timestamps. Uploaded artifacts — the Deliverables you upload, together with their metadata such as filename, size, and SHA-256 hash. Audit events — an append-only record of who did what and when in a deal room (uploads, invitations, reviews, acceptances, releases, certificate issuance).

Payment-confirmation references — when the Stripe-processed option is used, we receive and store a confirmation reference and limited transaction metadata from Stripe; when the attestation option is used, we store the parties' confirmation of an out-of-band payment. We do not collect or store raw card numbers or full payment credentials — those are handled directly by Stripe. We also collect basic technical and log data needed to operate and secure the Service.

3. How We Use It

We use personal data to: provide, operate, and improve the Service; authenticate you and keep your account secure; run controlled-handoff workflows between Sellers and Buyers; generate Certificates and maintain tamper-evident audit trails; send transactional communications such as invitations, handoff notifications, and certificate issuance; record payment confirmations; provide support; detect, prevent, and investigate fraud, abuse, and security incidents; and comply with legal obligations. We do not use your personal data for advertising, and we do not sell it.

4. Legal Bases for Processing (GDPR)

Where the EU or UK GDPR applies, we rely on the following legal bases under Article 6: performance of a contract (to provide the Service you or your organization requested); legitimate interests (to secure, maintain, and improve the Service, prevent abuse, and preserve the integrity of records, balanced against your rights); legal obligation (to meet regulatory, tax, and record-keeping requirements); and consent where we specifically ask for it, which you may withdraw at any time. Where we rely on legitimate interests, you may object as described in "Your Rights."

5. Storage and Security

Uploaded artifacts are held in private, access-controlled storage buckets; Buyers never receive a Seller's credentials or direct bucket access, and file access is mediated by the platform and only granted after the Release step. Database access is governed by Row-Level Security (RLS) so that each user can reach only the records for deal rooms they are part of. Data is encrypted in transit using TLS and encrypted at rest. Each artifact's SHA-256 hash lets us and the parties detect any change to a file, supporting the tamper-evidence of the audit trail and Certificate.

No method of transmission or storage is perfectly secure, but we maintain administrative, technical, and organizational safeguards designed to protect personal data appropriate to its sensitivity.

6. Third-Party Sub-processors

We use a small set of vetted providers to deliver the Service, each under agreements requiring appropriate data protection:

Supabase — database, authentication, and file storage. Vercel — application hosting and content delivery. Resend — transactional email delivery. Stripe — payment processing for the Stripe-processed option (Stripe handles card data directly; we receive only confirmation references and limited metadata).

If we add or change a sub-processor in a way that materially affects the processing of your personal data, we will update this policy and, where required, provide advance notice so you can review the change.

7. International Transfers

We and our sub-processors may process personal data in countries other than your own, including the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where relevant, the UK Addendum, together with additional measures as needed. You may request more information about these safeguards using the contact details above.

8. Data Retention

We retain account data while your account is active and for a reasonable period afterward to meet legal, tax, and security obligations. Certificates and audit events are retained by design: because their value depends on being a durable, tamper-evident record of a completed handoff, they are kept for the long term and are not routinely erased when other data is deleted.

You may ask us to delete your personal data (see "Your Rights"). We will honor valid requests for data we control, but we may retain, or retain in a minimized or de-identified form, records needed to preserve the integrity of Certificates and audit trails, to complete transactions, to resolve disputes, or to comply with law. Where a Certificate must reference a party, we will keep only what is necessary for it to remain meaningful and verifiable.

9. Your Rights

Depending on where you live, you may have rights to access the personal data we hold about you; to correct inaccurate data; to request deletion; to obtain a portable copy; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. Under the GDPR you also have the right to lodge a complaint with your supervisory authority. Under the CCPA/CPRA, California residents may request access, deletion, and correction, and may opt out of "sharing" or "selling" of personal information — and we confirm that we do not sell your personal data and do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights.

To make a request, email privacy@cendri.com. We will verify your request and respond within the timeframe required by applicable law. You may use an authorized agent where the law permits.

10. Invited Counterparties

When a user invites a Counterparty to a deal room, we process that person's email address and invitation-related data so we can deliver the invitation and enable the handoff, even before they create an account. If you received an invitation and believe it was sent in error, or you want your information removed, contact privacy@cendri.com. Note that a Counterparty's participation may still be reflected in a Certificate or audit trail for the deal room, as described under Data Retention.

11. Breach Notification

We maintain procedures to detect and respond to security incidents. If a breach affecting your personal data occurs, we will notify affected users and, where applicable, the relevant supervisory authorities without undue delay and consistent with our legal obligations, describing the nature of the incident and the steps we are taking.

12. Cookies

We use only essential cookies required to authenticate you and maintain your logged-in session. We do not use advertising or cross-site tracking cookies. If we ever introduce non-essential cookies, we will update this policy and, where required, ask for your consent first.

13. Children and Minimum Age

The Service is a business tool intended for users who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we will delete it. If you believe a minor has provided us personal data, contact privacy@cendri.com.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy with a revised "Last updated" date and, where appropriate, notify you. Your continued use of the Service after an update takes effect reflects your awareness of the current policy.

15. Contact

For questions about this Privacy Policy or our data practices, or to exercise your rights, contact us at privacy@cendri.com. For questions about the terms governing the Service, see our Terms of Service or write to legal@cendri.com.

© 2026 Cendri, Inc. All rights reserved.
Terms of ServicePrivacy Policy