01Who is responsible
Sanddo (and Sanddo.ai) is a brand and a service providing secure automation of customer service over email and messaging channels such as Facebook Messenger and Instagram. The service is operated by Citrus Consult ApS, company reg. no. (CVR) 46467981 (“Sanddo”, “we”, “us”).
For questions about this policy and the processing of personal data, contact us at hello@sanddo.ai. Citrus Consult ApS has not appointed a Data Protection Officer (DPO), as it is not legally required for the company.
02When this applies
This policy applies where Sanddo is the data controller — the data for which we determine the purposes and means. Primarily:
- visits to and use of our website,
- demo bookings and contact via forms or email,
- sales dialogue with current and prospective customers.
When Sanddo is used as a support tool by a customer, we process the data in that customer's support inbox as a processor on the customer's behalf and instructions. That is governed by a separate Data Processing Agreement (DPA) between the customer and Citrus Consult ApS — not by this policy. If you are an end customer who wrote to a company using Sanddo, that company is the controller for your correspondence.
Messaging channels: Facebook Messenger and Instagram
In addition to email, a business may connect its Facebook Messenger and Instagram accounts to Sanddo so that enquiries from those channels are handled in the same support flow. Here too the business is the controller and Sanddo is a processor acting on its instructions.
Once a business has connected a channel, we may process the following about you when you write to it:
- Message content — the text of your enquiry and any files or images you choose to send.
- A channel-scoped user id — Meta issues an identifier that is valid only for that business's app. It cannot be used to identify you across other services.
- Public profile name, where Meta makes it available, along with message timestamps.
The sole purpose is to answer your enquiry on the business's behalf. We do not use message data for marketing, ad targeting or profiling, and we do not combine it with data from other customers.
To draft a reply, the content of the enquiry is processed by the language-model provider described under Recipients and processors. Sensitive categories may require an employee to approve the reply first — see AI and automated decisions.
Order details require separate confirmation. A message on Messenger or Instagram carries no verified email address, so we cannot establish from the message alone that you own a given order. Specific order, delivery or return details are not disclosed in a message thread until ownership has been confirmed by other means. This is a deliberate choice, even when it makes the answer slower.
Deletion. If you remove the business's app from your settings at Meta, Meta automatically sends us a deletion request and we delete whatever we hold about you from that channel. You receive a confirmation code and a link where you can check the status. You may also contact the business you wrote to, or us at hello@sanddo.ai.
03Data we process
Depending on your contact with us, we may process:
- Contact details — name, work email, company, phone and title, if you provide them.
- Booking and dialogue data — chosen time, support volume, messages and notes from demos and conversations.
- Technical data — IP address, browser/device, language preference, necessary session data and standard server logs.
- Anything you send us — e.g. in emails or attachments.
We try to limit ourselves to what is necessary and do not ask for sensitive personal data in the sales dialogue.
04Purposes and legal basis
We process data for clearly defined purposes with the following legal bases under GDPR Article 6:
| Purpose | Legal basis |
|---|---|
| Answer enquiries and book demos | Pre-contractual steps and legitimate interest in dialogue with prospects (Art. 6(1)(b) and (f)) |
| Prepare and deliver a relevant walkthrough | Legitimate interest (Art. 6(1)(f)) |
| Operate, secure and improve the website | Legitimate interest (Art. 6(1)(f)) |
| Marketing emails to business contacts | Consent or legitimate interest with opt-out (Art. 6(1)(a)/(f)) |
| Non-essential cookies | Consent (Art. 6(1)(a)) |
| Comply with legal obligations, e.g. accounting | Legal obligation (Art. 6(1)(c)) |
Where a purpose relies on legitimate interest, we have assessed that our interest is not overridden by your rights. You can always object — see Your rights.
05AI and automated decisions
Sanddo's product uses artificial intelligence (large language models) to read support enquiries, look up relevant order and return data and suggest draft replies. We want to be open about how this works:
- No significant automated decisions about you on the website. On this website we do not make decisions based solely on automated processing that produce legal or similarly significant effects, per GDPR Article 22.
- Human-in-the-loop. In the product, sensitive categories — such as complaints, refunds and cancellations — can require an employee to approve a reply before it is sent. Automatic sending only happens in categories the customer has enabled.
- Transparency. Sanddo is built with the requirements of the EU AI Act (Regulation (EU) 2024/1689) in mind, including transparency, human oversight and the prohibition of certain AI practices.
- We do not train general models on customer data without a basis. Customers' support data is used to deliver the service to that customer — not to train general AI models — unless there is a valid, agreed basis.
The sub-processors providing the language models are listed under Recipients and processors. Read more about our security on the security page.
06Recipients and processors
We do not sell your data. We only share it with trusted vendors (processors) that process data on our instructions and under a data processing agreement, and where required by law. We typically use:
| Category | Vendors |
|---|---|
| Hosting and infrastructure | (application and database) |
| Email and calendar | Microsoft 365 / Outlook, Google Workspace and other IMAP/SMTP providers |
| AI / language models | (draft generation, via an underlying model provider, currently ) and Google / (embeddings and search) |
| E-commerce and support systems | Shopify, and Zendesk/Gorgias for history migration |
| Payment | Stripe. Web analytics is not active by default. |
An up-to-date and complete list of sub-processors is provided to customers as an annex to the Data Processing Agreement.
07International transfers
We aim to process data within the EU/EEA. Certain AI and payment vendors (incl. , Anthropic and Stripe) may process data in the US. This happens on the basis of the European Commission's Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework where the vendor is certified, supplemented by necessary safeguards. You can contact us for the basis and a copy of the relevant safeguards.
08Retention
We only keep data for as long as necessary for the purpose or as required by law:
- Demo and contact data: until the dialogue ends and for up to 24 months after, then deleted or anonymised.
- Customer relationships: for the term of the agreement. Accounting records are kept for 5 years after the end of the financial year, per the Danish Bookkeeping Act.
- Technical logs: for up to 90 days for operations and security.
When data is deleted, it is also removed from derived indexes and caches as far as technically possible.
09Your rights
Under the GDPR you have the right to:
- access the data we hold about you,
- have inaccurate data rectified,
- have data erased (“the right to be forgotten”),
- restrict processing,
- object to processing based on legitimate interest,
- receive your data in a structured format (data portability),
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
If you are an end customer of a company using Sanddo, please contact that company, which is the controller. We help our customers comply with such requests.
11Changes
We may update this policy, e.g. for new features or legal requirements. The current version is always here with an update date at the top. We will inform you of material changes where relevant.
12Contact and complaints
Questions or requests about your rights go to hello@sanddo.ai. We respond as soon as possible and within the GDPR deadlines.
If you disagree with how we process your data, you can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk, or your local supervisory authority.
We're happy to answer questions about data, security and data processing agreements.