Privacy Policy
How Send4.ai collects, uses, and protects personal data.
Last updated: 23 July 2026 · Version 2026-07-23
1. Who we are
Send4 ("Send4.ai", "we", "us") is an AI-assisted omnichannel messaging platform operated by Nord it, UAB, Ateities g. 5-86, LT-08305 Vilnius, Lithuania, company registration number 307668350.
For any privacy question or to exercise your rights, contact us at [email protected].
2. Our two roles: controller and processor
This policy covers the send4.ai website and the Send4 application. We process personal data in two distinct roles:
- As a controller — for the personal data of our own users and website visitors: account holders, team members invited to a workspace, and people who contact us. The sections below describe that processing.
- As a processor — for the personal data of our customers' contacts ("leads": for example their names, phone numbers, and message conversations). Our customer decides why and how that data is processed; we act only on their instructions under a data processing agreement. If you are a lead whose data is handled through Send4, the business you communicated with is the controller — please direct requests to them first. We assist them in responding, and you can always reach us at [email protected].
3. Personal data we collect as a controller
- Account data — your name, email address, optional company name, password (stored only as a cryptographic hash), locale and timezone, and role in your workspace.
- Google sign-in data — if you use "Continue with Google", we receive your name, email address, and Google account identifier from Google. We never receive your Google password.
- Consent records — the time you accepted our Terms of Service, how you accepted them (registration form, Google sign-in, or a workspace invitation), the versions of the Terms and of this Privacy Policy in force at that time, and the IP address and browser user-agent of the request. We keep these records as evidence that the agreement was made (legitimate interest), including after your account is closed or erased, for as long as legal claims arising from the agreement could still be brought — Article 17(3)(e) GDPR; generally up to 10 years under Lithuanian law — after which the IP address and user-agent are deleted.
- Usage and security data — login timestamps, IP address and browser user-agent for security logging, in-app activity events, and technical error reports.
- Communications — messages you send to our support channels.
- Demo request data — when you ask for a demo on send4.ai we collect your first and last name, email address, phone number and country, the team the demo is for, and the IP address the request came from (recorded for abuse prevention and included in the internal notification it generates). The form works in steps: if you fill in the first one and stop, we keep the name and email address you had already entered.
- Aggregated website analytics — we use Plausible, a cookie-less, privacy-friendly analytics tool that does not track individuals across sites and does not store personal profiles.
4. Purposes and legal bases (Art. 6 GDPR)
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and operating your account and workspace | Account data, Google sign-in data | Contract — Art. 6(1)(b) |
| Sending transactional email (verification, password, service notices) | Name, email address | Contract — Art. 6(1)(b) |
| Securing the platform: authentication, abuse and bot prevention, audit logging | Usage and security data, IP address | Legitimate interest — Art. 6(1)(f) (keeping the service secure) |
| Recording your acceptance of our terms | Consent records | Legal obligation / legitimate interest — Art. 6(1)(c), (f) |
| Diagnosing errors and improving reliability | Error reports (may include your user ID and email) | Legitimate interest — Art. 6(1)(f) |
| Understanding aggregate product usage | Cookie-less, aggregated analytics | Legitimate interest — Art. 6(1)(f) |
| Responding to your requests and support questions | Communications | Contract / legitimate interest — Art. 6(1)(b), (f) |
| Handling a demo request and texting or emailing you about it | Demo request data | Consent (the box you tick) and steps prior to a contract — Art. 6(1)(a), (b) |
| Following up on a demo form you started but did not finish | Name, email address | Legitimate interest — Art. 6(1)(f) (a single follow-up on a business enquiry you began); you can object at any time |
| Complying with law (accounting, legal claims, authority requests) | Any of the above, as required | Legal obligation — Art. 6(1)(c) |
5. AI-generated messaging
Send4 uses large language models provided by OpenAI to draft and send conversational replies on behalf of our customers. Message content and the conversation context needed to generate a reply are shared with OpenAI for that purpose. Under OpenAI's API business terms, data submitted through the API is not used to train OpenAI's models.
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing (Art. 22 GDPR). AI-generated replies are produced under the configuration and responsibility of the business using Send4, which can review and take over conversations at any time.
6. Who we share personal data with
We do not sell personal data. We share it only with service providers (sub-processors) that help us run the platform — hosting, messaging delivery, email, AI, and security. A demo request made on send4.ai reaches us by email through Resend (United States), and the form is protected by Cloudflare Turnstile. Every provider, with its purpose, location, and transfer safeguard, is listed at send4.ai/subprocessors.
We never sell, rent, or share mobile phone numbers or SMS opt-in data with third parties for their own marketing purposes, and we never share them with data brokers or lead-generation services. Where we act as a processor, lead phone numbers are used only to deliver the messages our customer has instructed us to send, through the messaging providers on that list. Consent a person gives to receive messages from one of our customers is never transferred to anyone else. If you gave us your own number in a demo request, we use it to contact you about that demo, and it is stored with the providers listed on that page.
We may also disclose personal data where required by law, to protect our rights, or as part of a corporate transaction (merger, acquisition), in which case this policy continues to apply.
7. International transfers
Some of our sub-processors are located in, or process data in, countries outside the European Economic Area — notably the United States. Where that happens, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where the provider is certified, the EU-U.S. Data Privacy Framework, together with additional technical safeguards such as encryption in transit and at rest. The safeguard that applies to each individual provider is shown on our sub-processor page; email [email protected] for a copy of the relevant safeguards.
The platform itself is hosted in the European Union (Frankfurt, Germany). Personal data of data subjects in the United Kingdom transferred onward to providers outside the UK is covered by the UK International Data Transfer Addendum to the SCCs, or by the UK's adequacy findings.
8. Retention
We keep your account data, and the lead and conversation data in your workspace, for as long as your account is open. We do not erase it on a fixed automatic schedule — your conversation history is the working record you rely on, so we keep it until you tell us otherwise.
You can have it erased at any time. Ask us at [email protected] — to close your account, to delete a workspace, or to erase specific data — and we will action the request within 30 days, as required by Art. 17 GDPR. Lead and conversation data that we process on behalf of a customer is erased when that customer instructs us to erase it.
Demo requests — including ones you started and did not finish — are kept in the notification email they generate, while the enquiry is live and for as long as we may still follow it up. There is no fixed clock; ask us at [email protected] and we erase them.
Two exceptions. We may keep limited records for longer where the law requires it (for example accounting records, which Lithuanian law requires us to retain for 10 years) or where we need them to establish or defend legal claims — such as the consent records described in Section 3, which survive account erasure. And security and application logs, which contain IP addresses and timestamps, are kept for no longer than 12 months.
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15);
- Have inaccurate data corrected (Art. 16);
- Have your data erased (Art. 17);
- Restrict processing (Art. 18);
- Receive your data in a portable format (Art. 20);
- Object to processing based on legitimate interests (Art. 21);
- Withdraw consent at any time, where processing is based on consent, without affecting prior processing (Art. 7(3)).
To exercise any of these rights, email [email protected]. We respond within one month. You also have the right to lodge a complaint with a supervisory authority — in particular the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), vdai.lrv.lt or the authority of your habitual residence.
If you are in the United Kingdom, the same rights apply to you under the UK GDPR and the Data Protection Act 2018, and you may complain to the Information Commissioner's Office (ICO), ico.org.uk.
10. If you are in the United States
Send4 is operated from the European Union and the platform is hosted on EU servers (Frankfurt, Germany); where a provider processes data outside the EEA — our transactional-email provider does — the safeguards described in Section 7 apply. The protections described in this policy apply to everyone: we do not run a weaker privacy regime for people outside Europe.
Where we handle personal information on behalf of a business customer, we act as that customer's "service provider" under the California Consumer Privacy Act (as amended by the CPRA), and as a "processor" under the comparable laws of Virginia, Colorado, Connecticut, Texas, Utah, and Oregon. That means we process personal information only to provide the service under our contract with that customer, and:
- We do not "sell" personal information, and we do not "share" it for cross-context behavioural advertising, as those terms are defined by the CPRA — we receive no money or other value for anyone's data;
- We do not retain, use, or disclose personal information for any purpose other than performing the service, or as otherwise permitted by law;
- We do not combine personal information received from one customer with data from another source, except as permitted to provide the service;
- We will notify the customer if we determine we can no longer meet these obligations.
If a business messaged you through Send4 and you want to exercise a right over your personal information (to know, delete, correct, or opt out), that business is the one that decides how your data is used — contact them first. We will help them respond, and you can always reach us at [email protected]. We do not discriminate against anyone for exercising a privacy right.
11. Cookies
The application uses only strictly necessary cookies: a session cookie and a CSRF protection token required to sign you in securely, and — if you choose "remember me" — a persistent login token. We do not use advertising or cross-site tracking cookies. Our website analytics (Plausible) works without cookies. Cloudflare Turnstile, our bot-protection service on the signup and demo forms, may set a strictly necessary cookie to distinguish humans from bots.
12. Security
We protect personal data with encryption in transit (TLS) and at rest, tenant isolation between customer workspaces, role-based access controls, audit logging, and continuous error and security monitoring. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the competent authority as required by Arts. 33–34 GDPR.
13. Children
Send4 is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy as the service evolves. We will post the new version here with an updated date and version number, and for material changes we will notify account holders by email or in the app before the changes take effect.