DeepSensi™

Privacy

Privacy by architecture.

DeepSensi™ is built so that privacy is not a policy you have to trust, but a property of the system itself. This notice explains, plainly, how this website handles personal data - wherever in the world you read it from.

Effective: July 11, 2026 · Controller: DeepSensi PBC, Dover, Delaware, USA · [email protected]

In three sentences: we never sell personal data; analytics run only after you explicitly consent; and the clinical platform itself is engineered to store zero personally identifiable information. The rest of this page is the detail behind those sentences.

1. Who we are

DeepSensi PBC, a Delaware public benefit corporation (Dover, DE, USA), operates this website (www.deepsensi.com) and the invitation-only documents portal (docs.deepsensi.com) and is the controller of the personal data described below. Privacy contact: [email protected].

2. What this website processes

2.1 Contact form

If you write to us, we process the details you submit (name, email address, topic, message) to respond to you and to keep a record of the correspondence. Legal basis (where one is required): steps you request prior to a possible relationship, and our legitimate interest in answering. Delivery is handled by Resend Inc. (USA) and our mail infrastructure; messages are routed internally by the topic you choose. Retention: up to 24 months after our last exchange, unless a continuing relationship requires longer.

2.2 Analytics - only after you consent

We use Google Analytics 4 with IP anonymization and without advertising features. It loads only after you explicitly accept it in the consent banner; declining is a single click and the site works identically. You can withdraw at any time: reset your analytics choice and the banner will ask again.

2.3 Hosting and security logs

The site is served by Cloudflare, Inc., whose infrastructure processes connection data (including IP addresses) for delivery and security with short technical retention. Basis: legitimate interest in operating a secure website.

2.4 Documents portal

Access to docs.deepsensi.com is by personal invitation. We process invitees’ names, email addresses, access tokens, and access logs (which documents were opened, and when) to protect confidential materials and to follow up on the engagement the invitee requested. Basis: the relationship with the invitee and our legitimate interest in protecting confidential information. Invitees are informed at invitation.

3. Cookies and local storage - the complete inventory

Before consent, this site sets no cookies. It uses two localStorage keys: ds-theme (your light/dark preference) and ds-consent (your analytics choice). After you accept analytics, Google Analytics sets its measurement cookies (_ga, _ga_*). There are no advertising cookies, no fingerprinting, and no cross-site tracking - on a site about privacy by architecture, that is not a coincidence.

4. Recipients and international transfers

We share personal data only with the processors named here: Google (analytics, after consent), Resend Inc. (email delivery), Cloudflare, Inc. (hosting, CDN, security), and our EU-based mail hosting provider. Some providers process data in the United States; transfers from the EEA/UK are protected by the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses. We do not sell personal data and we do not share it for cross-context behavioral advertising - with anyone, from anywhere.

5. Your rights - honored globally

Wherever you are, you may ask us for access to your data, a copy, correction, deletion, restriction, objection to processing, or portability, and you may withdraw consent at any time - write to [email protected]. We apply this baseline worldwide rather than arguing about which statute reaches whom. Regional specifics follow.

European Economic Area, United Kingdom, Switzerland

Legal bases are stated per activity above (GDPR Art. 6(1)(a), (b), (f); UK GDPR equivalents). You additionally have the right to lodge a complaint with your supervisory authority (in the UK, the ICO). We do not use your data for automated decisions with legal or similarly significant effects.

United States

We do not sell or share personal information as defined by the California Consumer Privacy Act and comparable state laws, and we honor access, deletion, and correction requests from residents of all states regardless of statutory thresholds. This website processes no protected health information and is not a HIPAA-covered service; the clinical platform’s data posture is described in section 8 and on the Technology page.

Brazil

For users in Brazil, processing rests on the legal bases of the LGPD corresponding to those above (Art. 7° I, V, IX), and you hold the rights of Art. 18, including confirmation, access, correction, anonymization, and deletion. Complaints may be directed to the ANPD.

Japan

For users in Japan, the purposes of use of personal information are those stated in section 2, per the Act on the Protection of Personal Information (APPI). We do not provide personal data to third parties other than the processors listed in section 4; where such processors operate outside Japan, we ensure protections equivalent to APPI standards through the safeguards described there. Requests for disclosure, correction, or suspension of use are honored via [email protected].

China (mainland)

If you access this site from mainland China, personal information you submit is processed outside China as described in this notice; by the separate, explicit consent actions on this site (the analytics banner; submitting the contact form) you consent to that cross-border handling per the Personal Information Protection Law (PIPL). We collect the minimum necessary, use it only for the stated purposes, and honor PIPL rights of access, copy, correction, and deletion. This website is provided in English and does not operate servers in mainland China.

Everywhere else

The same global baseline of section 5 applies, consistent with, among others, India’s DPDP Act, Korea’s PIPA, Singapore’s PDPA, South Africa’s POPIA, Nigeria’s NDPA, and Kenya’s Data Protection Act.

6. Retention - summary

Correspondence: up to 24 months after last exchange. Analytics: Google Analytics event data retained 14 months. Security logs: short technical windows set by our providers. Portal access logs: duration of the engagement plus 24 months. We delete earlier on valid request.

7. Children

This website is directed at professional audiences and is not intended for children under 16; we do not knowingly collect their data.

8. The platform - a different, stricter story

The DeepSensi™ clinical platform (distinct from this website) stores zero personally identifiable information. De-identification happens at the source, inside the clinical facility; cohort queries use k-anonymity (k ≥ 5); released aggregates draw on a pre-registered differential-privacy budget; every decision is recorded in an immutable, cryptographically anchored audit trail; and federation preserves national data sovereignty by default. Details: Technology.

9. Changes

Material changes to this notice will be posted here with a new effective date. Questions, requests, complaints: [email protected].