Embodied Assistant

Privacy Policy

1. Scope and responsibilities

This policy covers Embodied Assistant's product website, publisher-hosted assets, licensing and support. The publisher is Sentify Technology OÜ, registry code 17313430, Estonia. Our postal address is listed in the company details. Contact info@sentifyd.io or +372 56397185.

We are the controller of personal data we use to run these publisher activities. The owner of a WordPress site decides how its assistant is configured and is responsible for its visitors' data, hosting and AI provider arrangements. Merely supplying the plugin does not give us access to that site's database or make us its conversation processor. If separately agreed support requires access to personal data on your behalf, appropriate access and data processing arrangements must be agreed first.

If you are using an assistant on someone else's website, read that site's privacy notice and contact its owner about the conversation. This policy explains the standard plugin behaviour but does not replace that notice.

2. Conversations and data on the site owner's systems

The owner configures OpenAI or Microsoft Azure with their own credentials, which stay on the WordPress server. To establish a session, WordPress sends the provider settings, instructions, tool definitions and connection data. The browser connects to the provider for microphone audio, typed messages, conversation context and tool results. Results can include public site or product information and, when enabled, the visitor's WooCommerce cart. Providers also receive connection metadata such as IP addresses.

The plugin does not record audio in WordPress or send conversations or provider keys to a Sentify Technology conversation backend. Processing and retention by the selected provider depend on the owner's account, configuration and provider agreement. See OpenAI's privacy policy and Microsoft's privacy statement.

Settings and records reside on the owner's installation. Deactivation alone does not erase them. Uninstall cleanup depends on the owner's purge setting and whether another edition is active. Hosting logs, backups, WooCommerce records and other plugins have their own retention rules. The owner is responsible for deletion requests and site-specific retention.

3. Data we receive as publisher

4. Freemius and optional connections

When included in your distribution, the Freemius integration handles account connection, licensing and updates. Connecting or activating sends the account, site URL, plugin/environment and license details described on its screen to Freemius. Optional diagnostic or usage sharing follows the choices shown there. Free features do not require an account connection; the hosted Free download signup is a separate account flow. Paid license activation requires relevant licensing information.

Freemius handles its own checkout and account processing under its Privacy Policy and explains SDK collection in its data practices. Its hosted pages have their own cookies and notices. This integration is separate from visitors' AI conversations.

5. Why we use data and who receives it

We use order, license and support data to fulfil our contract with you or respond before you purchase. For business contacts acting for an organisation, we rely on our legitimate interest in managing that relationship. Our legitimate interests also cover delivering files, securing systems, preventing abuse and resolving support issues, balanced against your rights. We process records required for accounting or legal duties on the basis of those obligations. Where optional processing requires consent, we request it separately; merely reading this policy is not consent.

Relevant data may be handled by Microsoft Azure for hosting and asset delivery, Freemius for commerce and licensing, Web3Forms for contact-form delivery and spam prevention, and providers helping us with email, support and professional accounting or legal services. We limit access to what is needed for those functions. We may disclose information where required by law or necessary to establish or defend legal claims. We do not sell personal data, share it for cross-context behavioural advertising, or use plugin conversations to train our own AI models. We do not make solely automated decisions with legal or similarly significant effects about you.

Some recipients process data outside the European Economic Area. For transfers for which we are responsible, we use an applicable adequacy decision or appropriate safeguards, such as EU standard contractual clauses, where required. Contact us for information about the relevant safeguards or a copy. The site owner is responsible for transfers under its own hosting and AI provider arrangements.

6. Retention and security

We retain publisher-held data only for as long as necessary for its purpose: support correspondence while resolving a request and any related dispute; customer and license records while administering the relationship and applicable claims; and accounting records for statutory retention periods. Hosting and security records are subject to the hosting service's configuration and are retained as needed for delivery, troubleshooting or investigation. We delete or anonymise data when no longer needed, except records we must keep by law. Contact us for the period applicable to your records.

We use access controls and appropriate technical and organisational safeguards, but no system is entirely risk-free. Site owners are responsible for securing their WordPress installations, provider accounts and backups. Information required for a purchase, license or support request must be provided for us to fulfil that request; optional information is not required.

7. Your choices and rights

Depending on applicable law, you may request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. Email info@sentifyd.io; we may need proportionate verification and will respond within the applicable legal deadline. You may complain to the Estonian Data Protection Inspectorate or your local supervisory authority.

For conversations and records held by a site owner, contact that owner; we cannot retrieve or erase their database. You can stop an interaction, revoke microphone permission and clear browser storage. These actions do not erase data already held by the owner or AI provider. Manage Freemius account and privacy choices through its account tools or contact channels.

Our product sales and support are intended for adults administering websites. We do not knowingly seek children's personal data. Owners must assess their audience and implement any legally required safeguards or parental permissions before offering an assistant to children. Contact us if a child has supplied personal data to us.

8. Updates

We will update this page and its date when practices change, and give additional notice of material changes where required. New processing that requires consent will not be authorised simply by updating this policy.