Preview build — in active development. Account creation is closed and no data you enter here is kept. The full product is open as a demo: try the demo, or talk to Sunsato.

Legal

Privacy Notice

Effective date: 2026-08-06 · Version 2026-08-06

This document is a prepared draft. Fields shown in square brackets are pending completion by Sunsato and legal review; until they are filled in, treat this page as informational rather than final.

This notice explains what personal data ADE collects, why we process it, who else touches it, how long we keep it, and how you exercise your rights.

Who is responsible

[LEGAL ENTITY NAME], at [REGISTERED ADDRESS], is the controller for the personal data described here. Privacy questions go to [PRIVACY CONTACT EMAIL].

What we collect

  • Account data: email address, optional name, encrypted password (held by our authentication provider, never by us in readable form), and the version of the terms you accepted.
  • Workspace data: workspace names, membership and roles, and invitations you send or receive.
  • Content you upload: the datasets you provide and everything derived from them — analyses, decisions, and reports. These may contain personal data if you choose to include it; you decide what to upload.
  • Operational records: security and audit events (who did what, and when), server logs, and error reports.

Why we process it

To provide the service you asked for (performance of a contract), to keep it secure and prevent abuse (legitimate interest), and to meet legal record-keeping obligations. We do not use your operational data to train models for other customers, and we do not sell personal data.

Who else processes it

ADE runs on infrastructure operated by the providers below. Each processes data only to deliver its part of the service. We publish this list and will update it before adding a new provider.

  • SupabaseAuthentication, Postgres database, and file storage. ([SUPABASE REGION])
  • VercelApplication hosting, edge routing, and request logs. ([VERCEL REGION])
  • [EMAIL PROVIDER]Transactional email: account confirmation, invitations, password recovery. ([EMAIL PROVIDER REGION])

How long we keep it

  • Retained while the account is active, and deleted within 30 days of account deletion.
  • Datasets, analyses, decisions, and reports are retained while the workspace exists, and are deleted with it.
  • Audit records are retained for 12 months for security and dispute resolution.
  • Operational logs are retained for up to 30 days.

Your rights

You may ask what we hold about you, request a copy, have it corrected, or have it deleted. You may object to processing based on legitimate interest, and you may withdraw consent where processing relies on it.

Write to [PRIVACY CONTACT EMAIL]. We respond within 30 days. Turkish residents can find the KVKK-specific route on the KVKK notice page.

Cookies

ADE sets only the cookies required to keep you signed in and to remember your language choice. There is no advertising, profiling, or third-party analytics cookie, which is why you are not asked for cookie consent.

Security

Data is encrypted in transit, workspaces are isolated at the database level so one customer cannot read another's rows, sensitive actions are recorded in an audit trail, and access to production is limited to the operators who need it. No system is perfectly secure; report a suspected issue to the contact above.