01Encryption
Sanddo uses TLS for traffic and encrypts integration secrets server-side. OAuth tokens and API keys are never in the frontend, repo or logs.
02Access control
Access is granted on a least-privilege basis. Each customer's data is logically separated, and actions affecting a customer's end customers can be logged for traceability (audit trail).
03GDPR and data processing
Sanddo (Citrus Consult ApS) typically acts as a data processor for customers' support data. Customers must have a data processing agreement, and there must be clear processes for access, rectification, export and deletion. See also our privacy policy.
04Responsible AI
AI replies can run in draft, test or live mode. Sensitive categories — such as complaints, refunds, cancellations and angry customers — can require human approval before a reply is sent.
- Human oversight: automatic sending only happens in categories the customer has enabled.
- Transparency: built with the requirements of the EU AI Act (Regulation (EU) 2024/1689) in mind.
- Data discipline: customers' support data is used to deliver the service to that customer — not to train general models without a basis.
05Retention and deletion
Support emails, attachments, AI logs, prompts and embeddings are only kept for as long as necessary for the purpose. When data is deleted, it is also removed from derived indexes and caches as far as technically possible.
06Hosting and vendors
The application and database run on EU-hosted infrastructure. Reply drafts and indexing are generated by external language-model providers, and that processing takes place within the EU. Mail and calendar connect through your own Microsoft 365 or Google environment, and order, shipping and return data through the systems you have connected. We use only trusted sub-processors under a data processing agreement, and an up-to-date, complete list of sub-processors is provided to customers as an annex to that agreement (see the privacy policy).
07Report vulnerabilities
Send security reports to security@sanddo.ai. Do not access, alter or export data that is not yours. We acknowledge and handle reports as soon as possible.
We're happy to share the DPA and a list of sub-processors.