Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how Senderum Intelligence ("we," "us," or "our"), a product of eFulfilment, collects, uses, shares, and protects information when you or your business ("you," "the account holder") use Senderum Intelligence (the "Service"). We are established in the Netherlands and process personal data in accordance with the EU General Data Protection Regulation (GDPR).
This document is a draft written to match what Senderum Intelligence actually does today. It has not been reviewed by a lawyer and contains placeholders — marked like this — for facts we could not fill in automatically. Do not publish it until those are resolved and it has had a legal review.
1. Who this applies to
This policy covers admin accounts, employee/sub-user accounts, and anyone invited into a Senderum Intelligence workspace. Access to the Service is managed centrally through Senderum's single sign-on (SSO) service, which is covered by its own privacy terms; this policy covers what happens to your data once you're inside Senderum Intelligence itself.
2. What we collect
We collect and process the following categories of data:
- Account and identity data: name, email, account type (admin, employee, sub-user), role and permissions, and — for business accounts — the company details submitted during onboarding and verified against official Dutch Chamber of Commerce (KvK) records.
- Store and commerce data: when you connect a Shopify store, we read and store your orders, products, product variants, customers, and draft orders so we can generate demand predictions, stockout risk scores, and purchase/advertising recommendations. We also support custom and system API connections you configure yourself.
- AI agent and conversation data: messages sent to and from AI agents you configure, chat session history, saved charts, and an execution trace of what each agent did during a session (tool calls, timings, and outcomes) so its behavior can be reviewed and audited.
- Usage and platform data: API call logs, feature usage events, and error/service logs used to operate and improve the Service.
- Verification data: business registration details submitted for KvK verification, and — where a match can't be automatically confirmed — the follow-up explanation you provide to resolve the discrepancy.
3. How we use it
- To provide the Service: running SKU-level demand and stockout predictions, generating purchase order and advertising recommendations, producing scheduled AI summaries, and running the AI agents you configure.
- To verify business accounts against official KvK records during onboarding.
- To operate role-based permissions, sub-user access, and multi-tenant account structure.
- To maintain security, investigate misuse, and keep an audit trail of automated actions.
- To improve the Service's models and features, using aggregated or de-identified data where feasible.
4. AI processing and third-party model providers
Some features (agent conversations, AI-generated summaries, demand predictions) are powered by AI models. Data needed to complete a given request is sent to [name the underlying model provider(s), e.g. OpenAI / Anthropic / Azure OpenAI / self-hosted] for processing under their data-handling terms. We do not knowingly send more data than a given feature requires to function, and we do not train third-party foundation models on your data unless you're explicitly told otherwise for a specific feature.
5. Sharing your data
We share data only where necessary to run the Service:
- With Shopify, to read the store data you've authorized us to access.
- With the AI model providers described above.
- With [hosting/infrastructure provider], who host our infrastructure and databases.
- With official KvK data sources, to verify business registration details you submit.
- Where required by law, or to protect the rights, safety, or property of Senderum Intelligence, eFulfilment, or our users.
We do not sell your personal data.
6. Data retention
We retain account, store, and conversation data for as long as your account is active, and for [retention period] after closure, unless a longer period is required by law (for example, financial or verification records). You can request earlier deletion — see Section 8.
7. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in — an access_token and refresh_token set after SSO login — and session storage for temporary states like account emulation by support staff. We do not use third-party advertising or tracking cookies on the application itself.
8. Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data, subject to legal retention requirements.
- Request a portable copy of your data.
- Object to or restrict certain processing.
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.
To exercise any of these rights, contact us at [privacy contact email].
9. International transfers
Where data is processed outside the EU/EEA (for example, by an AI model provider or hosting service located elsewhere), we rely on [transfer mechanism, e.g. Standard Contractual Clauses] to keep it protected to an equivalent standard.
10. Security
We use role-based access controls, encrypted authentication tokens, and activity logging across the platform. No system is perfectly secure, and we encourage you to use strong, unique credentials and to review who has sub-user access to your account.
11. Children's privacy
Senderum Intelligence is a business tool and is not directed at, or intended for use by, children.
12. Changes to this policy
We'll update this page when our practices change and update the "Last updated" date above. Material changes will be communicated to account admins.
13. Contact
Questions about this policy or your data can be sent to [privacy contact email], or to [registered business address].