Legal
Privacy Notice
Effective and last updated: July 15, 2026
This notice explains how NEXUS AI, the operator of Senal Ops, handles personal data when you visit our website, create an account, contact us, or use the Senal Ops service.
Who is responsible for your data
NEXUS AI is the controller for website, account, sales, billing, and service-administration data. When customers submit telemetry, incident records, alert contacts, database backups, or other content to Senal Ops, the customer generally determines the purpose and means of processing and Senal Ops acts as its processor under the applicable agreement.
Privacy contact: [email protected]. Registered address: 3101 N Central Ave Phoenix, AZ 85012.
Personal data we process
- Account and identity data, including name, email, profile image, organization, membership, and authentication-provider identifiers.
- Commercial data, including plan, subscription, billing-customer identifiers, and transaction status. Payment card details are handled by Stripe.
- Service configuration, including monitors, services, alert destinations, on-call contacts, integrations, API-key metadata, and recovery settings.
- Customer content, including telemetry, logs, traces, incidents, reports, AI-agent runs, database backup artifacts, and information contained in customer-directed notifications.
- Technical and security data, including IP address, device and browser information, authentication events, audit records, request metadata, errors, and abuse-prevention records.
- Communications submitted through support, sales, security, or privacy channels.
Purposes and legal bases
- Provide and secure the service: performance of our contract and our legitimate interests in operating a reliable, secure platform.
- Accounts, authentication, support, and service notices: performance of our contract and steps requested before entering a contract.
- Billing and accounting: performance of our contract and compliance with tax, accounting, fraud-prevention, and other legal obligations.
- Product safety and improvement: our legitimate interests in diagnosing failures, preventing abuse, and improving service quality, balanced against individual rights.
- Optional marketing or non-essential device storage: consent where applicable. Consent may be withdrawn at any time without affecting earlier lawful processing.
- Legal claims and regulatory requests: compliance with legal obligations and our legitimate interests in establishing, exercising, or defending legal claims.
Sources of personal data
We receive data directly from users and customer administrators, from configured OAuth and notification providers, from payment and infrastructure providers, and automatically when the service handles requests. Customers may also submit data about their personnel, users, systems, or contacts; those customers are responsible for providing any notices required for that collection.
Recipients and subprocessors
We disclose data only as needed to operate the service, follow customer instructions, complete transactions, meet legal requirements, or protect rights and security. Categories include hosting and database infrastructure, email and messaging delivery, authentication, payment processing, AI services enabled by the customer, professional advisers, and public authorities where legally required. See our current subprocessor list.
International transfers
Providers may process data outside the country where it was collected. Where GDPR or similar rules require a transfer mechanism, we use an applicable adequacy decision, approved Standard Contractual Clauses, or another lawful safeguard. Information about the safeguard relevant to a customer deployment is available through our privacy contact or contractual documentation.
Retention
We keep personal data only for the period needed for the purposes above, the customer's selected plan and retention settings, and applicable legal, security, backup, dispute, and accounting requirements. Criteria and service-data categories are described in our data retention notice. When data is no longer required, we delete or anonymize it, subject to limited backup cycles and records we must retain by law.
Your privacy rights
Depending on your location and the circumstances, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent where processing relies on consent. You may also lodge a complaint with your local data protection authority. We may need to verify your identity and may retain limited records of the request.
Submit a request through the privacy request form or email [email protected]. Logged-in organization owners can also request an organization export or deletion from the Policies page. If Senal Ops processes the relevant data solely for a customer, we may direct the request to that customer as controller.
Automated processing and AI
Senal Ops may generate incident explanations, suggestions, classifications, or recovery recommendations. These features support human operational decisions; Senal Ops does not use them to make solely automated decisions producing legal or similarly significant effects about individuals. Customers should avoid submitting unnecessary sensitive personal data to AI features.
Security and breaches
We use technical and organizational safeguards designed for the nature of the service, including access controls, tenant scoping, encryption of protected credentials, audit logs, secret hashing, restore validation, and incident procedures. No system is completely secure. We investigate suspected personal-data breaches and provide legally required notices to customers, authorities, or affected people as applicable.
Cookies and browser storage
Senal Ops uses authentication, security, and preference storage needed to provide the site and dashboard. We do not currently use advertising or behavioral-tracking cookies. See the Cookie Notice for details.
Children
Senal Ops is a business service and is not directed to children. Do not create an account or submit personal data if you are not legally able to enter the applicable agreement.
Changes
We may update this notice as the service or legal requirements change. We will update the date above and provide additional notice when a material change requires it.