Trust

Privacy policy

This covers data about you, our customer. How we handle data about your contacts is a separate question, answered on the GDPR page.

Who is responsible

Kohi Solutions Ltd, str. Filip Simidov 1, entr. B, floor 3, apt. 11, Veliko Tarnovo 5000, Bulgaria, EIK 206220247, VAT BG206220247, is the controller for the personal data described here. Reach us at [email protected].

For the personal data of your contacts, which you upload or send to us through the product, you are the controller and we are your processor. See the GDPR and data residency page.

What we collect and why

When you join the waitlist

Your email address, and optionally what tool you currently use. We use it to contact you about beta access and nothing else. The legal basis is our legitimate interest in responding to someone who asked to be contacted. Ask us to remove you and we will.

When you hold an account

  • Account data: your name, email, password hash, and workspace settings. Needed to perform the contract.
  • Billing data: handled by our payment processor. We store the subscription state and invoices, not your card number.
  • Usage and diagnostic data: logs, error reports, and aggregate usage, used to keep the service working and to investigate faults. Legitimate interest.

When you visit this website: cookies and analytics

The site works without cookies. Two things can set them, and both are in your hands:

  • Your consent choice. Answering the cookie banner stores your answer in a cookie named sh_consent for one year, on sendheron.com and its subdomains, so we do not ask again on every visit. A second cookie, sh_region, may record whether you are in the EEA; it exists only to decide whether the banner needs to be shown and holds nothing else.
  • Google Analytics 4, provided by Google Ireland Limited, which tells us which pages get read. It sets no cookies unless you allow it on the banner; until you do, the script runs in a cookieless mode where requests to Google carry no analytics identifiers. If you allow it, it sets _ga cookies that last up to two years, and your visit data is processed by Google, including by Google LLC in the United States, under the safeguards described in the transfers section below. Declining changes nothing about how the site works.

The legal basis for analytics is your consent; for the consent cookie itself it is our legitimate interest in remembering your answer. You can change your mind at any time: .

How long we keep it

  • Waitlist entries: until the beta closes or you ask us to delete you, whichever comes first.
  • Account data: for as long as your account exists. You can delete it yourself from Settings, then Security, then Delete account. The data goes 14 days after you ask, sending stops the moment you ask, and you can call it off until the day it runs. The GDPR page sets out what an owner's request covers and what survives it. Backups age out on their own retention cycle.
  • Invoices and tax records: for as long as EU and Bulgarian accounting law requires, which is longer than we would otherwise keep them, and which is why they outlive a deleted account.
  • Proof that a deletion happened: one row per deleted account, kept as our record that the erasure was carried out. It holds a hashed form of the email address rather than the address itself, so it can show that an account was erased without recording whose it was.

Who else sees it

Only the sub-processors we use to run the service, each of which is listed on the GDPR page along with what it does. We do not sell personal data, and we do not share it for anyone else's advertising.

Data that leaves the EU

Your contact data is stored and processed in the EU, and all email is sent from Frankfurt. Some of the providers we rely on are outside it: the GDPR page names each one and where it processes. Today those are our CDN and object storage provider, the model behind AI onboarding, our error monitoring, and, if you allowed it, analytics on this website.

Each of those transfers stands on a recognised safeguard under Chapter V of the GDPR: Cloudflare, Stripe, Sentry (Functional Software, Inc.) and Google LLC are certified under the EU-US Data Privacy Framework, and for OpenAI we rely on the standard contractual clauses in its data processing addendum. We would rather name the transfers than describe the service as EU-only and leave you to discover otherwise.

When authorities ask

We disclose data to authorities only where we are legally obliged to, and we will tell you when we are permitted to tell you.

Your rights

Under the GDPR you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Email [email protected] and we will answer within one month.

Deletion has a faster route than writing to us. If you can log in, you delete the account yourself from Settings, then Security, then Delete account, and the GDPR page describes exactly what that removes. The address above is for everything else, and for deletion when you cannot get into the account.

If you think we have handled your data badly, you can complain to the Bulgarian Commission for Personal Data Protection, or to the supervisory authority where you live. We would rather you told us first so we can fix it.

Security

Data is encrypted in transit. Access to production systems is limited to the people who need it. API keys are scoped, so a key you issue for one job cannot quietly do another. No system is perfectly secure, and anyone who tells you otherwise is selling something.

Changes to this policy

If we change this materially, we will say so on this page and, for account holders, by email. We will not make a quiet change and rely on you re-reading it.