Legal

Privacy Policy

How we handle the information you submit through this website, what our infrastructure records automatically, how long we keep it, and the rights you can exercise.

Effective 2026

On this page

  1. 01 Scope of this policy
  2. 02 Information you provide to us
  3. 03 Information collected automatically
  4. 04 How we use information
  5. 05 Legal bases for processing
  6. 06 Sharing and disclosure
  7. 07 International transfers
  8. 08 Retention
  9. 09 Security
  10. 10 Your rights and choices
  11. 11 Government and defense correspondents
  12. 12 Third-party sites and services
  13. 13 Changes to this policy
  14. 14 Contact
01

Scope of this policy

This policy explains how we, SENTIAT Corp, handle information in connection with this website, including our public pages, our contact form, and the restricted Technology and Programs areas that open with an authorized access code.

It does not govern information exchanged under a separate written instrument such as a non-disclosure agreement, teaming agreement, program agreement, contract, cooperative research arrangement or investor agreement. Where such an instrument applies, its terms control for the information it covers.

It also does not govern information you provide directly to a third party, including a partner, integrator, hosting provider, event organizer or platform where you may encounter our material.

This policy is written for a business, institutional, government and defense audience. It is not directed to children, and we do not knowingly collect information from children.

02

Information you provide to us

Inquiry information. When you contact us through the site, you may provide your name, your organization, command or agency, your role, your email address, an inquiry type, and the contents of your message. Provide only what is needed for us to route and answer your inquiry.

Credential information. If our Chief Executive Officer or Chief Operating Officer issues you an access code, we process your entry of that code in order to grant or deny access. We may associate an issued code with the recipient organization or program office for accountability.

Correspondence. If our exchange continues by email, call or meeting, we retain the business-contact details and the substance of that correspondence in our records as an ordinary business record.

What not to send. Do not submit classified information, controlled unclassified information, export-controlled technical data, operational or program-sensitive details, sensitive categories of personal data, health or financial data, or third-party proprietary information through this site or by unencrypted email. If you send it anyway, we may delete it and, where required, report it through the appropriate channel.

03

Information collected automatically

Our hosting, delivery and security infrastructure records ordinary technical request data such as IP address, approximate coarse location derived from IP, browser and device type, operating system, referring page, requested URLs, response codes, timestamps and request volume.

We use this technical data to keep the site available, to detect and mitigate abuse such as scraping, credential-guessing and denial-of-service activity, to diagnose faults, and to maintain security records.

Access-control events, including successful and unsuccessful attempts to unlock restricted areas, may be logged as a security measure.

The site uses only the storage strictly necessary to operate, including session state that remembers whether your browser has been granted access to a restricted area. We do not use advertising cookies, cross-site tracking pixels, or third-party behavioral profiling on this site.

We do not respond to browser Do Not Track signals in a standardized way, because we do not conduct cross-site behavioral tracking to begin with.

04

How we use information

To receive, route, evaluate and respond to your inquiry, and to continue the discussion with you or your program office.

To grant, deny, monitor, rotate and revoke access to restricted Technology and Programs material.

To operate, maintain, secure, troubleshoot and improve the website and its content.

To protect the integrity of our information, our intellectual property and our pending patent matters, and to investigate suspected misuse.

To comply with law and with our own obligations, including export control, sanctions screening, procurement integrity and record-keeping requirements.

To establish, exercise or defend legal claims where necessary.

We do not use information submitted through this site for advertising, and we do not use it to train third-party generative models.

05

Legal bases for processing

Where data protection law such as the GDPR or UK GDPR applies to you, we rely on the following bases. Legitimate interests, for responding to business inquiries, operating and securing the site, and protecting our rights. Contract, where processing is necessary to take steps at your request before entering into an agreement or to perform one. Legal obligation, where retention, screening or disclosure is required by law. Consent, only where we specifically ask for it, in which case you may withdraw it at any time.

06

Sharing and disclosure

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Service providers. We share information with vendors that host, deliver, secure, monitor or support this site and our business communications. They act on our instructions under contractual confidentiality and security obligations, and may not use the information for their own purposes.

Internal recipients. Access inside SENTIAT Corp is limited to personnel who need the information to respond to you, administer access, or maintain security.

Professional advisors. We may share information with counsel, auditors, insurers and similar advisors under confidentiality obligations.

Legal and safety. We may disclose information where required by law, subpoena, court order, regulatory or government request, or where we reasonably believe disclosure is necessary to investigate suspected fraud, unauthorized access, export-control violations, or threats to the rights, safety or property of any person.

Corporate transactions. If we are involved in a financing, merger, acquisition, reorganization or asset sale, information may be transferred as part of that transaction, subject to protections consistent with this policy.

07

International transfers

We are a United States company and our infrastructure and personnel are primarily located in the United States. Information you send us will be processed in the United States and may be processed in other countries where our service providers operate.

Where required, we use appropriate safeguards for cross-border transfers, such as standard contractual clauses or an equivalent recognized mechanism, and we assess our providers accordingly.

Some information may be subject to United States export control and sanctions law, which can restrict onward transfer irrespective of data protection considerations.

08

Retention

We retain inquiry and correspondence records for as long as needed to handle your inquiry and to maintain a reasonable business record of the engagement, then delete or archive them under our retention schedule.

Security and access logs are retained for a limited period appropriate to security monitoring and incident investigation, and longer where an investigation or legal hold requires it.

Records tied to contracts, export-control determinations, financial matters or intellectual property may be retained for longer periods required by law, regulation or a governing agreement.

When retention is no longer required, we delete the information or place it beyond further use.

09

Security

We apply administrative, technical and organizational measures intended to protect information handled through this site, including encryption in transit, restricted internal access on a need-to-know basis, credential-based gating of sensitive material, and logging of access events.

Security is a shared responsibility. Protect any access code issued to you, do not reuse it elsewhere, do not circulate it, and tell us promptly if you believe it has been exposed or if a holder leaves your program.

No transmission or storage method can be guaranteed completely secure. If we become aware of an incident affecting information you provided, we will act on it and provide notice where law or a governing agreement requires.

If you believe you have found a vulnerability in this site, report it to us through the contact page before disclosing it elsewhere, and do not access, alter or exfiltrate data belonging to others while investigating.

10

Your rights and choices

Depending on where you are located, you may have rights to request access to the information we hold about you, correction of inaccurate information, deletion, restriction of or objection to certain processing, portability, and withdrawal of consent where consent was the basis.

United States state privacy laws may additionally give you rights to know, delete, correct, opt out of sale or sharing, which we do not conduct, and to be free from discrimination for exercising those rights.

To exercise a right, contact us through the contact page and describe your request. We may need to verify your identity and your authority before acting, and we will respond within the period required by applicable law.

We may decline or limit a request where retention is legally required, where the information relates to a pending legal matter, where release would compromise security, export-control compliance or the rights of others, or where an exception otherwise applies. We will explain the reason where we are permitted to.

If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your supervisory authority.

11

Government and defense correspondents

If you contact us in an official capacity, we treat your business-contact details as official correspondence and handle them as an ordinary business record. Your own agency records, retention and disclosure rules may also apply to that correspondence independently of this policy.

This site is not an authorized channel for classified or controlled information of any kind. If a matter requires a controlled channel, tell us and we will arrange one before you send anything.

12

Third-party sites and services

Our pages may link to third-party resources, partner organizations or research materials. Those destinations have their own privacy practices, which we do not control and are not responsible for. Review their policies before providing information to them.

13

Changes to this policy

We may update this policy as our practices, technology, service providers or legal obligations change. The current version is always posted on this page, and the effective date reflects the latest revision.

Where a change materially affects how we handle information you already provided, we will take reasonable steps to inform you.

14

Contact

Privacy questions, rights requests, credential-exposure reports and security concerns may be directed to SENTIAT Corp through the contact page on this site. Please label urgent security or export-control matters clearly so we can route them immediately.