While you browse

Reading the site collects nothing.

  • No analytics, no tracking, and no advertising technology.
  • No cookies or browser storage are set while you read the site.
  • Fonts are served from this site; no third-party services are contacted as you browse.
  • Standard server request logs may exist at the hosting layer for security and reliability; they are not used to profile visitors.

When you define a mandate

What you send, and what is recorded.

The Define a mandate flow, and the RFP, NDA-first, and inquiry routes, collect only what is needed to judge fit and prepare a first conversation. You decide how much to write; “not yet known” is a valid answer throughout.

What you write
The operating problem and context you describe in your own words — what must change, what happens today, the consequence, what success looks like, the environment and boundaries, ownership, and readiness.
How to reach you
Your name, organization, role, and work email, plus optional preferred language, time zone, and whether to begin under standard confidentiality or an NDA first.
Your consent
A record that you agreed to this notice: the version of the notice and the moment you submitted. There is no marketing consent to give — this site does not do marketing.
A reference and its status
A generated reference code so you can amend or withdraw, and the route and processing state of your mandate (received, under review, and so on). No field values are written to application logs.

The one cookie

The mandate flow uses a single, essential session cookie so the steps remember what you entered as you move between them. It holds only an opaque session identifier — your entries are kept server-side for a short time — and it is not used for analytics or tracking. No cookie is set unless you begin a mandate. The full detail, including the security challenge on those pages, is set out in the Cookie Policy .

Checks that protect the form

A human check (Cloudflare Turnstile)
The mandate pages load Cloudflare Turnstile to tell people from automated abuse. Only on those pages, Cloudflare receives the challenge interaction and your IP address to return a verification result. If you have JavaScript disabled the form still works; the submission is simply flagged for a person to review.
Rate limiting
To blunt automated floods, a short-lived counter is kept against a salted, one-way hash of your IP address. The raw IP address is not stored for this purpose, and the counter expires automatically.
Quiet integrity checks
A hidden field and a minimum time-to-complete help detect scripted submissions. They record no information about you.

Why it is held, and for how long

Your information is used to assess whether SageTensor is the right fit, and to prepare and hold a first conversation. It is kept only for that purpose and only for as long as that purpose is live.

Mandate, RFP, and NDA requests
Up to 12 months from your last contact, then deleted.
General inquiries
Up to 6 months, then deleted.

What SageTensor does not do

  • No marketing, no newsletters, and no sale or sharing of your information for advertising.
  • No profiling and no automated decision that affects you — a person reads every mandate.
  • No public file upload; any document exchange happens later over a channel arranged with you.
  • No account and no password to manage; the reference code is all you need to amend or withdraw.

Amend or withdraw

Keep the reference code shown when you submit. With it, you can ask SageTensor to correct or delete your mandate before or after it is reviewed — write to privacy@sagetensor.com with that code. Whether or not you make such a request, deletion still runs automatically on the schedule above.

How it is protected

  • Submissions travel over an encrypted connection and are stored in a managed database, written only through parameterized queries.
  • Application logs record operational events — route, reference, timestamps — never the words you wrote or your contact details.
  • Retention is enforced by an automated job, and a mandate can be placed on legal hold where a legal obligation requires it.

Why we may use your information

Data-protection law (including the EU and UK GDPR) asks us to name the basis on which we use your information. Ours are:

To assess fit and reply (legitimate interests)
We use what you send to judge whether SageTensor is the right fit and to prepare and hold a first conversation. This is our legitimate interest, and yours, in exploring working together; it is balanced against your rights and involves no marketing or profiling.
To act on your request (steps toward a contract)
Where you ask us to begin under an NDA, or to respond to an RFP, we process what is needed to take those pre-contract steps at your request.
To record consent
We keep a record that you agreed to this notice — the version and the moment — as evidence of consent where consent is the basis for a specific step.
To keep the service safe and lawful (legitimate interests / legal obligation)
We run proportionate anti-abuse checks to protect the service, and we retain limited records where a legal obligation requires it.

Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • Access — a copy of the information we hold about you.
  • Rectification — correction of anything inaccurate or incomplete.
  • Erasure — deletion of your information where there is no overriding reason to keep it.
  • Restriction and objection — to pause or object to our use of your information.
  • Portability — to receive what you gave us in a portable form.
  • Withdraw consent — at any time, where consent is the basis, without affecting prior processing.

If you are a California resident, the CCPA (as amended by the CPRA) gives you the right to:

  • Know — what personal information we collected, and why.
  • Delete — the personal information we hold about you.
  • Correct — inaccurate personal information.
  • No sale or sharing — we do not sell or share your personal information, so there is nothing to opt out of.
  • No discrimination — you receive the same service whether or not you exercise a right.

To exercise any of these, write to privacy@sagetensor.com — quoting your reference code if you have one. We will respond within the time the law allows (for the GDPR, within one month; for the CCPA, within 45 days), and we will not charge you or treat you differently for asking.

Where your information is processed

SageTensor is based in the United States, and its infrastructure provider operates globally, so your information may be processed in the United States. Where information protected by UK or EU law is transferred outside those regions, the transfer relies on an appropriate safeguard — such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. The providers involved are named in the Data Processing Addendum .

Complaints

If you are not satisfied with how we have handled your information, please raise it with us first at privacy@sagetensor.com .

You also have the right to complain to a data-protection authority — in the EEA or UK, your local supervisory authority; in California, the California Privacy Protection Agency or the Attorney General.

Who is responsible, and how to reach us

The controller responsible for your information is SageTensor LLC, a limited liability company formed under the laws of the State of Wyoming, United States of America. You can reach us about privacy at privacy@sagetensor.com , about security at security@sagetensor.com , or by post at:

Full company details are on the legal and company identity page .

Changes to this notice

We will update this notice as our practice and the law evolve. The “last updated” date at the top reflects the current version, and we will make a material change here before it takes effect, not after.