Privacy Policy
How Sagaris collects, uses, shares, and protects personal data — stated plainly, including where our customers control the data and we act on their instructions.
Last updated July 4, 2026
Who we are and what this policy covers
Sagaris ROS is an AI-native revenue operations platform — CRM, outbound sequencing across email, phone, SMS, and LinkedIn, an AI agent layer, and deliverability tooling — operated as a multi-tenant SaaS by Sagaris (“Sagaris”, “we”, “us”).
This policy covers personal data we process when you visit our websites, sign up for or use the platform, or communicate with us. It also explains our role when customers upload their own contact data into their workspace: for that data, our customer is the data controller and Sagaris acts as a processor on their instructions.
Information we collect
We collect the following categories of information:
- Account information: your name, company email address, and workspace membership. Authentication uses Google Identity Platform session cookies with company-email confirmation codes.
- Workspace content: the CRM records, contact lists, notes, sequences, templates, and files that you or your teammates add to your workspace.
- Communications content: emails, call recordings and transcripts, SMS messages, and meeting notes generated when you use the platform's outreach and calling features.
- Usage and device data: server logs with request correlation IDs, security and audit events, and product analytics (we use PostHog) about how the application is used.
- Billing information: subscription and payment records processed by Stripe. Full card numbers are held by Stripe, not by Sagaris.
How we use information
We use personal data to operate, secure, and improve the platform:
- Providing the service: running your CRM, sequences, dialer, mailboxes, and integrations you connect.
- AI features: workspace content may be sent to our AI providers (Vertex AI Gemini as the primary model; OpenAI and Anthropic as optional fallbacks) to generate drafts, summaries, transcripts, and recommendations for your workspace.
- Your data is not used to train shared models. Workspace records serve that workspace only — this is a product trust boundary shown to every workspace owner in the product.
- Security and compliance: authentication, fraud and abuse prevention, audit trails for exports, imports, and AI-initiated actions, and enforcement of outbound-consent rules.
- Support and communication: responding to requests and sending service or billing notices.
Contact data our customers bring
Customers upload prospect and contact data into their workspaces. For that data, the customer decides what is collected and how it is used; Sagaris processes it to provide the service.
The platform is consent-first by design: a per-contact, per-channel consent ledger with regional rule sets (GDPR, CAN-SPAM, TCPA, CCPA/CPRA, CASL, PECR) and non-overridable safeguards such as mandatory unsubscribe links, explicit opt-in for SMS, and do-not-call screening. Opt-outs are honored immediately across all sequences for that channel.
If you believe a Sagaris customer has contacted you improperly, or you want your data removed from a customer's workspace, contact us and we will route the request to the responsible workspace and apply suppression where required.
How we share information
We do not sell personal data. We share it only with service providers (subprocessors) that help us run the platform — cloud hosting and AI infrastructure (Google Cloud Platform, Vertex AI Gemini, and optional OpenAI/Anthropic fallbacks), communications providers (Telnyx, Twilio, Resend, ElevenLabs), business services (Stripe, Apollo.io, Perplexity), and the third-party integrations you choose to connect (such as Salesforce, HubSpot, Gmail/Google Calendar, Microsoft Outlook, LinkedIn, X).
Several providers only process data when you enable the relevant feature or integration. A summary is published on our Trust & Security page, and a full subprocessor list with purposes and data categories is available to reviewers on request.
We may also disclose information when required by law, or as part of a corporate transaction, in which case this policy will continue to apply to previously collected data.
Data retention and deletion
We keep personal data for as long as your workspace is active or as needed to provide the service, comply with legal obligations, and resolve disputes.
The right to erasure is implemented in the product: personal data is anonymized, hashed suppression records prevent silent re-import of erased contacts, and a verifiable deletion certificate is produced. Contact and workspace data can be exported in CSV form, and data-subject-request activity is tracked against statutory deadlines.
How we protect data
The platform runs on Google Cloud Platform (Cloud Run and Cloud SQL PostgreSQL) in the us-east4 region. TLS protects data in transit, data at rest uses GCP-managed encryption, and high-value credentials such as OAuth tokens are additionally encrypted with AES-256-GCM at the application layer. Access is workspace-scoped with a least-privilege, fail-closed role model.
We describe our security posture — including what is still in progress — on our Trust & Security page. We do not claim certifications we do not hold.
Your privacy rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the processing of your personal data, and to object to certain processing (including under the GDPR and CCPA/CPRA). You will not be discriminated against for exercising these rights.
To exercise a right, email us at the address below. If your data lives inside a customer's workspace, we may need to refer your request to that customer as the controller, and we will support them in fulfilling it. A dedicated self-service request portal is on our roadmap.
International data transfers
Sagaris is operated from the United States, and the platform stores data in the us-east4 (Northern Virginia, USA) region by default. If you use the platform from outside the United States, your data will be transferred to and processed in the United States and in the countries where our subprocessors operate.
Cookies and analytics
We use cookies that are necessary to operate the service — primarily secure, httpOnly session cookies for authentication — and product analytics (PostHog) to understand how the application is used so we can improve it. We do not run third-party advertising trackers on the platform.
Changes to this policy and how to reach us
We may update this policy as the product and the law evolve. We will change the “last updated” date above and, for material changes, notify workspace owners through the product or by email.
Questions, privacy requests, and complaints can be sent to support@sagaris.ai. We acknowledge privacy requests promptly and track them against statutory deadlines.