Privacy Policy
Last updated: August 11, 2026
- Who we are
- Data we collect
- How we use data
- Model engines & processing location
- Model training
- Sharing
- Retention & deletion
- Security
- Your rights
- Cookies
- Changes
- Contact
1. Who we are
SolvFast ("SolvFast", "we", "us") operates Senaiy Lab, a platform where organizations build and run AI agents on their own knowledge, connected to their systems (the "Platform"), available at platform.senaiy.ai and associated domains, including the developer console and APIs. This Privacy Policy explains how we collect, use, protect, and retain personal data and customer content when you visit our websites or use the Platform.
For the purposes of applicable data-protection law, SolvFast is the controller of account and billing data, and the processor of content you submit to the Platform on behalf of your organization.
2. Data we collect
- Account data — name, business email address, organization name and role, and login credentials (passwords are stored only as salted hashes).
- Billing data — top-up and invoicing records, wallet balance, and transaction history. Card payments are handled by our payment processor; we do not store full card numbers.
- Customer content — the prompts, documents, knowledge zones, agent definitions, workflow definitions, and tool configurations you submit to the Platform, and the outputs generated from them ("Customer Content").
- Usage and audit data — request metadata (timestamps, API key and project identifiers, model tier, token counts, cost), request logs, and the tamper-evident audit trail that records who executed what, with which agent, on which model tier, which knowledge classification was retrieved, which tools were called, and where processing took place.
- Technical data — IP address, browser and device information, and server logs collected when you access our websites and APIs.
3. How we use data
- To provide, operate, and secure the Platform, including authentication, routing, metering, and billing.
- To enforce knowledge-classification and routing policies you configure.
- To produce the usage records, spend dashboards, and audit trails that the Platform exists to provide.
- To respond to support requests and communicate service or security notices.
- To monitor for abuse, fraud, and violations of our Terms.
- To improve the Platform using aggregated, de-identified usage statistics that do not include Customer Content.
- To comply with legal obligations.
We do not sell personal data, and we do not use Customer Content for advertising.
4. Model engines and processing location
The Platform routes requests to model engines according to the model tier you select and the policies you configure:
- Cloud engines are operated by third-party model providers on their infrastructure and under their terms. When your request is routed to a cloud engine, the content of that request is processed by the relevant provider as our subprocessor.
- In-region engines run on infrastructure in the region managed for Senaiy Lab. Where your policy or a knowledge classification requires it, the Platform enforces in-region processing and records it in the audit trail.
The audit trail shows, for every request, which engine processed it and where — this is how you can verify residency rather than take it on trust.
5. Model training
We do not use your Customer Content — your prompts, documents, knowledge, or your agents' outputs — to train machine-learning models.
6. Sharing
We share personal data only with:
- Subprocessors engaged to provide the Platform — hosting and infrastructure providers, third-party model providers (for requests you route to cloud engines), and our payment processor — under contracts that restrict their use of the data to providing services to us.
- Legal authorities, where required by applicable law or a binding order, in which case we will notify you unless prohibited from doing so.
- A successor entity in a merger, acquisition, or asset sale, subject to this Policy.
A current list of subprocessors, and our data-processing agreement (DPA), are available on request at the contact below.
7. Retention and deletion
- Account and billing data are retained for the life of the account and thereafter as required for tax, accounting, and legal purposes.
- Customer Content is retained while your account is active and deleted or returned on verified request or account closure, subject to a reasonable export window.
- Usage and audit records are retained for as long as needed to support billing disputes, security investigation, and the audit guarantees of the Platform.
8. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit, encryption of stored secrets, role-based access controls, tenant isolation, scoped per-agent tool access, and a tamper-evident audit chain. No system is perfectly secure; we encourage you to use strong credentials and to scope API keys narrowly.
9. Your rights
The Platform is designed to support the requirements of the Saudi Personal Data Protection Law (PDPL) and Egypt's Personal Data Protection Law (Law 151/2020). Depending on the law that applies to you, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent.
To exercise these rights, contact us at the address below. If you are an end user of one of our customers, we may refer your request to that customer, who controls the content processed on their behalf.
10. Cookies and similar technologies
We use only functional cookies: session cookies for authentication in the console, and small preference cookies (for example, remembering a dismissed announcement). We do not use advertising or cross-site tracking cookies. Our pages load fonts and scripts from third-party CDNs (Google Fonts, jsDelivr); those providers receive your IP address as a technical consequence of serving the files.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced on this page with an updated date, and — for significant changes affecting Platform customers — by notice to your account email. Continued use of the Platform after a change takes effect constitutes acceptance of the revised Policy.
12. Contact
For privacy questions, data-subject requests, our subprocessor list, or a DPA, contact appbuilder@solvfast.com.
This Policy is drafted in English; translations may be provided for convenience, in which case the English version prevails.