Skip to content
sandadocs

Privacy and your data

Which consent prompts you will meet, what sanda collects, what reaches an AI model, how long data is kept, and how to ask for your information.

This page explains in plain terms what sanda's privacy policy says, and where in the product you meet it. The policy is the authority. If this page and the policy ever differ, the policy wins.

sanda is run by Sanda Technologies Pty Ltd (ABN 63 702 995 015, ACN 702 995 015). The company is responsible for the personal information the policy describes, and it is the other party to the terms.

Two facts sit under everything else. sanda does not sell your data and does not use it to train anything. And it is your data: what you connect, upload or generate stays yours, and sanda takes no licence to it beyond running the service for you.

At sign-up, you accept the terms and the privacy policy. The sign-up form has an unticked box naming both, each linked. sanda will not create a workspace without it. sanda records which dated version of each you were shown, when you accepted, and from where. You can ask sanda for that record at any time.

Every person accepts the privacy policy in the console. The first time anyone signs in, including a teammate who joined by invitation, the console shows the whole policy in place of every page, with its effective date and version. To go on, they tick I have read and agree to sanda's privacy policy and press Agree and continue. The acceptance is recorded with the version, the moment and the address it came from, and cannot be edited afterwards. When the policy changes, every person is asked again.

If someone does not agree, they can sign out. sanda cannot be used without accepting. They can still send a support message.

Integration tokens and connected apps are not asked. The person who made one meets the prompt the next time they sign in.

An owner decides about sanda search. sanda search sends text from your tables to an embedding model outside Australia, so it is off for every new workspace and only a workspace owner can switch it on. The owner presses Switch sanda search on under Intelligence · Vector search, after reading what is sent. Switch it off later pauses every service and sends no further text. An admin cannot make this choice.

On the sanda website, you choose about analytics. The website sets no advertising or tracking cookies. A banner asks you to Allow or Decline cookieless page-view counting, and nothing loads until you answer. If your browser already sends a Global Privacy Control or Do Not Track signal, sanda treats that as a decline and does not ask. You can change your answer at any time from the privacy policy page.

What sanda collects

The policy describes three kinds of information, kept apart.

What you tell sanda. When you sign up: your name, email, company and, if you choose to give it, your role. sanda sends email only about your account and the product.

Your business data. Whatever your connected sources contain, synced into a warehouse that belongs to your workspace and no other. sanda does not choose what is in it, does not mine it and does not use it to train anything.

That includes your conversations with cherry. sanda keeps your chat history, with the questions, the answers and the rows of data behind each answer, so you can come back to it. It belongs to your workspace and is deleted when you delete the conversation or close the workspace.

If your sources hold personal information about your own customers or staff, sanda handles it on your instructions. You stay responsible for it, and for having the right to connect it.

What using sanda produces. Sign-in events, sync outcomes, error logs, and a record of which pages and features your workspace used, by whom, and whether each request worked. That includes the network address and browser details of each sign-in. For AI features, sanda records that a request ran, which model answered and what it cost, not what was asked. This is what lets sanda tell you why a sync failed, keep your account secure and bill by usage.

AI and your data

sanda uses AI models to answer questions and to help you build your model. To be useful, a model has to see enough. Depending on the feature, a request can contain:

  • your question and the recent messages in the conversation;
  • the names of your tables and columns, and the definitions your workspace has agreed;
  • a small sample of real values from your columns, so the model can tell what a column holds;
  • the rows a query returns;
  • your name, your role and your workspace's name, so the assistant knows who it is talking to.

Columns whose names suggest secrets, such as passwords, tokens, tax file numbers and card numbers, are never sampled or returned. Other columns are not filtered by their content. If a column holds personal information, such as email addresses, a sample of it can be sent.

Requests go through a routing service in the United States to the company that runs the model. sanda only sends requests to endpoints that do not keep what they receive and do not train on it. If no such endpoint exists for a model, the request is not sent. Models run outside Australia, mostly in the United States.

sanda does not use personal information to make decisions about individuals. Its models write queries and draft reporting, and people decide what to do with the results. Automatic limits, such as pausing a workspace at a spending limit, apply to the whole workspace and not to any person.

If an owner switches on sanda search, the text of the columns you choose to index is sent to an embedding model in the United States, along with the text of each search. Columns used only to filter stay in your warehouse. The model returns a list of numbers for each piece of text, and sanda stores those in your own warehouse in Sydney beside the rows they came from. A column whose name says it holds a secret is refused outright, and a column that looks like a personal detail is flagged to whoever sets the service up.

Leaving sanda search off means the text in your tables is never indexed. It does not stop the other AI features from working as described above.

Limiting AI use

Every AI call sanda makes for your workspace counts against a daily limit that your owners and admins control. See Budgets and AI limits.

How long sanda keeps it

What How long
Your warehouse and everything in it Until you delete it or close your workspace. A closed workspace stays readable for 90 days so you can export what you need, then it is permanently deleted
Search indexes With the search service that made them. Removing a service deletes its index
Chat history Until you delete the conversation or close your workspace
Account details While your account is open, then deleted with your workspace
Activity and error logs 30 days
Security audit records For the life of the workspace, then deleted with it
Backups 30 days, then overwritten
Invoices, and the record that you accepted the terms and policy Kept after your account closes because the law requires it. Invoices are kept for at least 5 years
Enquiries and support messages As long as needed to deal with what you asked. Ask and sanda will delete them

What closing does, step by step, is in Close or delete a workspace.

Your rights

You can ask sanda for a copy of the personal information it holds about you, ask it to correct or delete that information, or export your workspace and take it elsewhere. Your warehouse is standard PostgreSQL, so an export is a database rather than a proprietary file.

Write to privacy@sanda-os.com.au. sanda aims to reply within 5 working days, and always within 30 days. It will confirm it is you first, and there is no charge. If it cannot do what you ask, for example because the law requires a record to be kept, it tells you why in writing. Deleting your information can mean closing your account.

If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Something unclear or out of date? Tell us, and we will fix the page.