Privacy policy
This policy covers the personal data Saifuro handles on its websites, in email, in hiring and in its product. Statements on this page about our systems describe how they are set up on the effective date below.
The short version
Contents
Who we are and what this covers
Saifuro LLC decides why and how the personal data described here is used. Under the GDPR and the UK GDPR, that makes it the controller.
What this policy covers
Our websites: saifuro.com, the documentation at docs.saifuro.com, the sign-in page at app.saifuro.com and the key server at verdicts.saifuro.com. The API at api.saifuro.com. Email sent to any @saifuro.com address. Data about our customers and their contact people. Our hiring, up to a signed offer. Our official channels on social networks, as far as we control them.
What it does not cover
Personal data that our customers send through the Saifuro API about their own users or counterparties. We process it on the customer's behalf under our agreement with them, as section 04 explains.
Websites and services run by other companies, including the social networks where we publish and the job boards where our roles appear. Their own policies apply there.
What we collect
What we receive depends on how you reach us. The cases below start with a plain visit.
When you visit our sites
Every request to our sites passes through Cloudflare, which forwards it to a server we rent from a hosting provider. Cloudflare passes your IP address on to that server, and our web server writes it to its access log together with other details that depend on the site:
Request bodies are never logged, so nothing you type into a form reaches these logs. To slow down abuse, the server also counts requests per IP address. Those counters live in memory and are never written to disk.
Fonts, the bot check and error reports
Pages on saifuro.com load their fonts, Geist and JetBrains Mono, from Google Fonts. Your browser therefore sends Google a request that carries your IP address and browser details. Because of our referrer policy, Google learns only that the request comes from saifuro.com, not which page you are reading. The documentation at docs.saifuro.com serves its own fonts and loads nothing from other domains.
Every page on saifuro.com except the not-found page also loads the script for Cloudflare Turnstile, the check that keeps bots away from our demo form. The check itself runs only on the home page, where the form is, and there it runs as the page loads, before you type or send anything. Other pages just download the script. During the check your browser exchanges technical signals with Cloudflare, such as your IP address and details of your browser and connection. Usually you see nothing.
The Turnstile frame on the home page also saves an entry named cf.turnstile.u in your browser's local storage. The frame comes from Cloudflare, so our own pages cannot read the entry, and current browsers keep such storage separate for each site you visit. Cloudflare describes the signals it uses in its Turnstile privacy addendum.
Our responses also ask browsers that support Network Error Logging to report to Cloudflare when a request to our sites fails. Successful page loads are not reported.
When you ask for a demo
The form on our home page asks for your name and work email, which are required, and optionally your company and a message. It also sends your use case, one of four options, with the first one preselected. Along with these it sends a hidden field that only bots fill in, a Turnstile token and how long the page was open before you pressed send. All three exist to filter out bots. None of them is saved with your request, apart from the result of the Turnstile check. When the request reaches our server, the form service handles it like this:
Drops the request without storing or forwarding it if the hidden field is filled in or the form was sent less than three seconds after the page opened. The page still shows the usual confirmation. Refuses, with a message, more than five requests an hour from one IP address and requests without a name or a valid email address.
Sends the Turnstile token and your IP address to Cloudflare to confirm that a person sent the request. If the check fails, the request is refused, and nothing is stored or forwarded. If Cloudflare cannot be reached, the request goes through marked as unchecked.
Adds the request to a file on our server: the fields you filled in, the time, your IP address and the result of the check. Fields are cut at 100 characters for the name, 200 for email, company and use case, and 2,000 for the message. The service does not forward the request anywhere.
When it drops a request, refuses it as a bot or for too many requests, or stores it, the service writes your IP address and the outcome to the server's system journal, without your name or email.
We reply by email from an @saifuro.com address, and the conversation continues there. If we arrange a call, the invitation names the video service it runs on, and that service handles call data under its own terms.
When you email us
Email to any @saifuro.com address, including contact@, security@ and the addresses of individual team members, is hosted by Zoho Mail on its EU service. We receive your address, the name your mail program sends with it, what you write, any attachments and the technical headers every message carries. Our replies, and the service email the Saifuro platform sends to customer contacts, go out through Zoho too.
If you report a security issue to security@saifuro.com, we use the report and your contact details to investigate, fix the issue and reply to you.
On social networks and Telegram
We publish on X, LinkedIn, Medium and a Telegram channel, all listed on Linktree. On our sites these are plain links, so nothing loads from those networks until you follow one. If you follow us, comment or message us there, the network handles your data under its own policy, and we see what it shows us, such as your public profile and what you wrote.
On our LinkedIn page, LinkedIn also gives us statistics about visitors and followers, called Page Insights, and shows us who follows the page. LinkedIn and Saifuro are joint controllers of Page Insights under LinkedIn's Page Insights Joint Controller Addendum, in which LinkedIn takes responsibility for informing you and for answering requests about that data. The other networks may show us similar statistics about our posts and followers under their own terms.
Some team members list their own LinkedIn, X or Telegram accounts on our About page. A message sent there reaches that person through that network. How we use these networks in hiring is described in section 03.
Job applicants
This section applies from the moment you apply for a role, or we contact you about one, until a signed offer. To check that a hiring conversation really is with us, see our hiring safety page.
Customers and the product
Access to the Saifuro product runs under a separate agreement signed at onboarding. The data involved falls into two groups, and our role is different for each.
Data about our customers
When a company is onboarded, we record its name and the email address of the contact person it gives us. We issue API credentials and keep only a one-way hash of each key plus a short hint, so we can tell keys apart without being able to read them. Requests to the API are logged, including the IP address they come from, so we can run and secure the service. When someone at a customer raises a support request, we track it in Linear, as section 06 lists. For this data Saifuro is the controller.
Data our customers send through the API
Mandates, agents, payment requests, verdicts, escrow records and webhook addresses can contain personal data about a customer's own users or counterparties, for example a name in a mandate or an identifier in free-form metadata. We process that data only to provide the service to the customer, under our agreement with them. For this data the customer is the controller and Saifuro is a processor. The customer's privacy policy applies to it, not this one, and our agreement with the customer sets how long it is kept. If you think your data is in a customer's account, contact that customer. If you write to us, we will point you to them.
Where the platform runs
The Saifuro platform, which runs the policy engine, the decision log and customer environments, is hosted on Amazon Web Services in the eu-central-1 region in Frankfurt. Our documentation names the platform's subprocessors and what each one sees in its subprocessors list.
The sign-in page
The sign-in page at app.saifuro.com does not create accounts or sessions. If you type an email address and press sign in, the page sends only that address. Our server replies that access has not been set up, and it does not store, forward or log the address. The password field is never sent anywhere, even with scripts switched off. The access log records the request itself like any other, without what you typed. The page loads nothing from other domains, and apart from the error reporting setting described in section 09, it stores nothing in your browser.
Documentation and the key server
The documentation at docs.saifuro.com loads nothing from other domains and sets no cookies. If you switch the color theme or pick a tab, your browser remembers that choice in its own storage, and it never leaves your device. The API explorer in the docs does not save a key you paste into it, and sending live requests from it is switched off. The key server at verdicts.saifuro.com serves only the public keys used to check a signed verdict. Requests to both are logged as section 02 describes.
Purposes and legal bases
Under the GDPR and the UK GDPR, every use of personal data needs a legal basis. Where the basis is our legitimate interests, the interest is named below. You never have to give us personal data. The demo form does need a name and a work email, and an application needs a way to reach you; without them we cannot reply.
Visiting our sites
IP address, the URL requested and the response status; the time everywhere except saifuro.com. On docs, app and verdicts also the referrer and user agent. Error logs also record the referrer when your browser sends it.
Delivering pages and keeping the sites up and secure. The logs are also how we trace errors and abuse.
Legitimate interests: running a website that works and stays secure.
Access logs about two weeks, error logs longer (section 08).
Cloudflare protection and the bot check
IP address, request details, signals from your browser and connection, the entry the Turnstile frame saves on the home page, the result of the check.
Blocking attacks and automated abuse, and keeping bots away from the demo form.
Legitimate interests: protecting our sites and the people who use the form.
Cloudflare keeps what it collects under its own policy (section 06). The result of the check is stored with a demo request.
Google Fonts
IP address, browser details, the fact that the page is on saifuro.com.
Showing our pages in their typeface.
Legitimate interests: a consistent presentation of the site.
Under Google's own policy (section 06).
Demo requests
Name, work email, company, use case, message, time, IP address, the result of the bot check.
Replying to you and following up on the demo you asked for.
Legitimate interests: answering business inquiries. Where you act for yourself, steps you asked for before a contract.
See section 08.
Address, name, content, attachments, message headers.
Replying and keeping a record of the conversation.
Legitimate interests: running our business correspondence. A contract, where we have one with you.
See section 08.
Social networks and Telegram
What you send us there, what the network shows us about you and, on LinkedIn, the page statistics.
Replying to you and running our channels.
Legitimate interests: talking to people who reach us there and understanding who reads what we publish.
On the network under its own rules. Anything we copy into email is kept as email (section 08).
Job applications
Contact details, application material, messages, scheduling, interview notes and assessments, outcomes. For people we contact first, the profile or other source that led us to them.
Assessing candidates and hiring.
Steps you asked for before a contract. For people we contact first, legitimate interests: finding candidates for open roles.
See section 03.
Keeping an application for future roles
Your application material and contact details.
Considering you for roles that open later.
Your consent, which you can withdraw at any time.
For the period we name when we ask, or until you withdraw your consent.
The paid work sample
What you deliver and the record of paying you for it.
Carrying out the work sample, paying for it and keeping the payment record.
The agreement for the work sample. For the payment record, our legitimate interests in complying with the accounting and tax laws that apply to us.
The payment record as long as accounting and tax law requires. The rest as for applications.
Customer contacts and API accounts
Organization name, contact email address, key hash and hint, logs of requests to the API, support requests, the platform's operational logs.
Providing the service to the customer, answering its support requests, and running and securing the platform and access to it.
Performance of our agreement with the customer. For its contact person, legitimate interests: working with our customer.
See section 08.
Server security
IP addresses of blocked connections and of attempts to log in to our website server.
Protecting that server.
Legitimate interests: the security of our systems.
Weeks to months (section 08).
Legal requirements
Any of the above, as far as needed.
Meeting legal obligations and lawful requests, and dealing with legal claims.
Legal obligation, where EU or UK law imposes it. Otherwise, our legitimate interests in complying with the laws that apply to us, such as US law, and in establishing or defending legal claims.
As long as the obligation or the claim requires.
Who receives it
The providers below receive personal data because we use them to run our sites, email, the Saifuro platform and hiring. The links under each name go to its own privacy terms. If you do the paid work sample, the payment also passes through the payment method we agree with you.
Our websites and email
The network in front of all our sites: encrypted connections, caching, protection from attacks and bots including Turnstile, the redirect to HTTPS and network error reports. Cloudflare processes our traffic under its data processing addendum; for Turnstile, its Turnstile privacy addendum also applies.
RECEIVESAll traffic between you and our sites, which includes your IP address and anything you send in a form, and the signals the Turnstile check collects in your browser.
WHERECloudflare's global network. Your traffic is handled at one of its locations, usually one near you.
Our hosting provider
Runs the server that hosts our websites and some of the services that support them, including the demo form service.
RECEIVESTechnical access to everything stored on that server, because it runs the hardware underneath, such as logs, demo requests and backups.
WHEREThe United Kingdom.
Serves the fonts of saifuro.com and handles these requests under its own privacy policy.
RECEIVESYour IP address, browser details and the fact that the request comes from saifuro.com.
WHEREGoogle's infrastructure, which includes the United States.
Zoho (Zoho Mail)
Hosts all email for @saifuro.com addresses, including the service and support email of the Saifuro platform.
RECEIVESEvery email you send us and every email we send you.
WHEREZoho's EU service.
The Saifuro platform
These four process data on our behalf for the platform and for customer support. They appear, together with Cloudflare and Zoho above, in the subprocessors list in our documentation.
Hosts the Saifuro platform: the policy engine, the decision log and customer environments.
RECEIVESDecision records, policy configuration and agent identifiers, including any personal data a customer puts in them.
WHEREThe eu-central-1 region in Frankfurt, in the European Union.
Captures and tokenizes card credentials at the edge, before they reach Saifuro.
RECEIVESCard data sent through the platform. Primary account numbers never enter Saifuro's own systems.
WHEREThe European Union.
Monitors the platform's infrastructure and holds its operational logs.
RECEIVESOperational telemetry and system logs of the platform.
WHEREThe European Union.
Tracks support requests and engineering issues.
RECEIVESThe contents of support requests that customer contacts raise with us.
WHEREThe United States.
Hiring and social platforms
We use these platforms to publish and to talk to candidates. Each acts on its own account, under its own terms and privacy policy, not on our behalf, apart from LinkedIn's page statistics described below. X, Medium and Linktree, where we also have accounts, receive no personal data from us; if you use them, their own policies apply (section 02).
Hosts our company page and the messages we exchange with candidates there. For the page statistics, LinkedIn and Saifuro are joint controllers, as section 02 explains.
RECEIVESMessages you exchange with us there. For our page, visits and follows, from which it builds the statistics it shows us.
WHERELinkedIn's infrastructure, which can be outside the UK and the EEA.
Indeed
A job board where some of our openings are listed and where we sometimes write to candidates first.
RECEIVESYour application, and the messages we exchange with you there, only if you apply there or we write to you there.
WHEREIndeed's infrastructure, which can be outside the UK and the EEA.
Telegram
Carries our official channel and messages with the team members whose accounts are on our About page, including messages with candidates. We see what Telegram shows us about you, such as your name and username.
RECEIVESMessages you exchange with us there.
WHERETelegram's infrastructure, which can be outside the UK and the EEA.
We may also disclose personal data when the law requires it, for example under a valid court order; when we need to establish, exercise or defend legal claims; to protect people's safety or the security of our systems; or to a successor if Saifuro is merged or sold, in which case this policy keeps applying to the data.
International transfers
Saifuro LLC is a company in the United States, so what you send us goes to a US company. Our team works remotely from wherever its members are. The providers in section 06 handle data in these places:
Cloudflare's data processing addendum is part of its standard terms and relies on the EU-US Data Privacy Framework and on standard contractual clauses. Linear's standard data processing addendum forms part of its terms and covers transfers from the EEA with the EU standard contractual clauses and from the UK with the UK addendum to them. Google, LinkedIn, Indeed and Telegram handle what they receive under their own terms and privacy policies, linked in section 06. If you have a question about how a transfer of your data is protected, write to contact@saifuro.com.
How long we keep it
Each entry gives a fixed period where one exists, and otherwise the rule we apply. The entries for web server logs, the system journal, server security logs and backups describe our website server.
How we protect it
If a personal data breach is likely to put you at high risk, we will tell you without undue delay, and we will notify the supervisory authority where the law requires it. To report a vulnerability, see our security page or security.txt.
Your rights
If you are in the European Economic Area or the United Kingdom, the GDPR or the UK GDPR gives you the rights below. We honor the same requests from anyone, wherever they live.
Your right to object
You can object at any time to any use of your data that relies on our legitimate interests, which covers most of what this policy describes. We then stop, unless we have compelling grounds that override yours or need the data for legal claims. If you ask us to stop sending you follow-up emails, we stop, without exceptions.
Access
Get a copy of your data and an explanation of how we use it, including where we got it if not from you.
Correction
Have inaccurate or incomplete data put right.
Deletion
Have your data deleted when we no longer need it or have no basis to keep it. For backups, see section 08.
Restriction
Have us pause the use of your data while a question about it is being resolved.
Objection
Object to any use based on our legitimate interests, as described above.
Portability
Receive the data you gave us in a machine-readable format, where we process it on the basis of consent or a contract.
Withdrawing consent
Withdraw consent at any time where we rely on it. What we did before stays lawful.
Complaint
Complain to us or to a data protection authority, as described below.
How to make a request
Write to contact@saifuro.com, ideally from the email address the request is about. If we cannot tell that the request comes from you, we will ask for the minimum needed to confirm it. We answer within one month. For a complex request we can extend that by up to two more months, and we will tell you why within the first month. Requests are free of charge.
Where to complain
You can complain to us at contact@saifuro.com. We acknowledge a complaint within 30 days and tell you the outcome without undue delay.
You can also complain to the data protection authority in the EEA country where you live or work, or where you think the problem happened (list of authorities), or in the UK to the Information Commissioner's Office (ICO). The ICO usually expects you to raise a complaint with us first.
US state privacy rights
Saifuro does not sell personal information and does not share it for cross-context behavioral advertising, as California law uses those terms. We do not use sensitive personal information to infer characteristics about anyone.
Wherever you live in the United States, you can ask us what personal information we have collected about you, and ask for a copy, a correction or deletion. We will not treat you differently for asking. Send requests to contact@saifuro.com. An authorized agent can make a request for you with your signed permission, and we may ask you to confirm your identity with us directly. If we decline your request, you can ask us to reconsider by replying to our answer, and we will tell you the result.
In the last 12 months we collected these categories of personal information, as California law names them: identifiers such as name, email address and IP address; internet or other electronic network activity, meaning server logs; and professional or employment-related information from job applications and from the profiles of people we contact about a role. Their sources, purposes, recipients and retention are described in sections 02 to 08.
Automated decisions
Saifuro's product returns signed verdicts on payment requests made by our customers' software agents. A verdict applies rules the customer has written, on the customer's behalf, to a transaction that software proposed. It is an authorization decision about a payment, not an assessment of a person by Saifuro. Where a customer's rules affect people, the customer decides how, and its own policy explains it.
The automated checks on our own sites decide only whether traffic looks like a bot or an attack: Cloudflare's protection and, for the demo form, the Turnstile check, a hidden field, a minimum time on the page and a limit on how often one address can send. A request that fills in the hidden field or is sent within three seconds of the page opening is dropped without being stored, while the page still shows the usual confirmation. If you do not hear back from us, or your request is refused by mistake, email contact@saifuro.com and a person will read it.
Saifuro's own systems make no other decisions about visitors, people who contact us or applicants, and build no profiles of them. If a decision about you is ever made solely by automated means with legal or similarly significant effects, you can ask for a person to review it.
Children
Our sites and services are for businesses and professionals and are not directed at children under 16. We do not knowingly collect their personal data. If you believe a child has sent us personal data, tell us and we will delete it.
Changes to this policy
When we change this policy, the new version appears on this page with a new effective date, and the history below records the change.