Privacy policy for Pensero AI software

Effective Date: July 22, 2026

This Privacy Policy explains how Pensero Inc. ("Pensero", "we", "us", or "our") collects, uses, discloses, and protects personal information in connection with:

Our Service: Pensero owns and operates the Pensero AI Software ("Service"), which is licensed to our customers. Under this licensing arrangement, the customer's employees (the "End Users") are granted access to and use of the Service. In this context, Pensero processes End-User data strictly following the customer's documented instructions and solely to provide, support, and improve the Service.

Our Website: We also process personal data collected through our website for these primary purposes:

  • To allow potential customers (leads) to request more information or a demo (collecting identifying and contact data).

  • To collect traffic, location, and commercial information (including managing landing pages, performing heat mapping and session recording, testing new features, and optimizing site traffic) based on our legitimate interests to enhance customer service, analyze software practices, and inform strategic development and growth decisions.

  • With your consent, to measure the performance of our marketing campaigns and, where applicable, to deliver and measure advertising, using cookies and similar technologies from providers such as Google, Meta, LinkedIn and Microsoft.

This Privacy Policy is published on our website and applies globally. It is organized into a Generic Section (applicable to all jurisdictions) and three Specific Sections addressing the relevant legal requirements under US law, UK law, and the GDPR (where applicable).

I. Generic Section (Applicable to All Jurisdictions)

1. Scope and Purpose

a) Service Data: Pensero processes personal data of End Users (employees of our customer companies) solely for the provision, support, improvement, and evolution of the Service. In this capacity, Pensero strictly follows our customers' instructions (who are the Data Controllers).

b) Website Data: For visitors to our website, we process personal data for:

  • Managing requests for information or demos (collecting identifying and contact data).

  • Collecting and analyzing traffic, location, and commercial data to optimize our website's performance, manage landing pages, perform heat mapping and session recording, test features, and optimize traffic based on our legitimate interests.

  • With your consent, measuring our marketing campaigns and delivering and measuring advertising through cookies and similar technologies.

2. Information We Collect

2.1 In Connection with the Service

Based on our customer's instructions, we may collect:

  • Identifiers: Names, email addresses, and user account credentials that enable access to the Service.

  • Employment Information: Data related to performance metrics, job roles, activities, and individual contributions provided by the customer (e.g., via integrations with tools like Slack or Jira) or generated by our proprietary AI. Such data, which evaluates employee contributions over time, is treated as personal data.

  • Usage Data: Automatically collected data from interactions with the Service (e.g., login times, IP addresses, usage patterns) to enhance security, monitor performance, and continuously improve the Service.

2.2 Through Our Website

When potential customers interact with our website, we may collect:

  • Identifying and Contact Data: When requesting more information or a demo, information such as names, email addresses, and phone numbers.

  • Traffic and Location Data: Data regarding the user's navigation (e.g., IP address, device type, geolocation, pages visited) for analytical purposes.

  • Commercial Information: Data that reflects user interest in our products and services.

  • Additional Processing for Optimization: Data used for managing landing pages, heat mapping and session recording, testing new features, and optimizing site traffic, collected based on our legitimate interests to implement improvements aimed at user experience.

  • Advertising and Marketing Data: With your consent, online identifiers (such as cookie IDs and device identifiers) processed through advertising and analytics technologies to measure our campaigns and, where applicable, deliver advertising.

2.3 Cookies and Similar Technologies

We use cookies, web beacons and pixels, analytics tools, and heat-mapping and session-recording tools on our website. Strictly necessary cookies are always active; analytics and advertising cookies are set only with your consent. For the full list of cookies we use, their purpose and duration, and to manage your preferences, please see our Cookie Policy and our cookie banner.

3. How We Use the Information

3.1 Use of Data in Connection with the Service

We use End User data exclusively to:

  • Provide the Service: Authenticate users, grant access, and ensure the intended functionality of our AI software for productivity and performance management.

  • Support and Maintain: Offer technical support, resolve issues, and ensure continuous Service improvement.

  • Legitimate basis: The processing activities outlined are necessary to fulfill contractual obligations with the Customer. Additionally, the company has a legitimate interest in improving its service and maintaining security, provided that such interests do not override users' fundamental rights and freedoms. These interests include preventing fraud, detecting unauthorized access, and ensuring the integrity of its systems.

  • Compliance and Security: Meet legal obligations and safeguard the security and integrity of the data.

  • AI/ML Training Limitations: Pensero does not use any collected data to develop, improve, or train generalized AI and/or ML models. In particular, data from Google Workspace APIs is never used for such purposes.

3.2 Use of Data Collected Through Our Website

We use website data to:

  • Manage Requests: Process inquiries, demo requests, and information requests from potential customers.

  • Optimize and Analyze: Monitor traffic, perform heat mapping and session recording, test features, and optimize the website to improve user experience and our marketing strategies.

  • Advertising and Campaign Measurement: With your consent, we use advertising and marketing cookies and similar technologies (for example from Google, Meta, LinkedIn and Microsoft) to measure the performance of our marketing campaigns, understand which channels bring visitors to our website, and where applicable to deliver and measure advertising. These technologies may share online identifiers with the relevant advertising providers, who may act as independent controllers or as our processors depending on the technology. You can accept or decline these technologies in our cookie banner and can withdraw consent at any time.

3.3 Legal Bases (Website)

We process contact and demo-request data based on our legitimate interest in responding to your enquiry and pursuing new business, and to take steps at your request before entering into a contract. We use non-essential cookies and similar technologies (analytics and advertising) only based on your consent, which you give through our cookie banner and can withdraw at any time. Strictly necessary cookies are used based on our legitimate interest in operating and securing the Websites.

4. Who We Share Data With

We share website personal data with the following categories of third parties:

  • Hosting and infrastructure providers (for example Amazon Web Services and Framer).

  • Analytics providers (for example Google Analytics, PostHog and Microsoft Clarity).

  • Advertising and campaign-measurement providers (for example Google Ads, Meta and LinkedIn).

  • Our server-side tagging provider, used to route measurement data.

  • Customer relationship and marketing tools (for example HubSpot).

We share only what is necessary for these purposes and require these providers to protect personal data. Some providers may act as independent controllers for their own purposes; please review their own privacy notices. We do not otherwise sell your personal data for money (see the USA section regarding "sharing" under the CCPA/CPRA).

5. International Data Transfers

We are based in the United States and use service providers located in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), with supplementary measures where necessary. You can request more information about these safeguards using the contact details below.

6. Data Security

Pensero implements appropriate administrative, technical, and physical safeguards to protect personal data against unauthorized access, alteration, loss, or disclosure. Key measures include:

  • Encryption: Personal data is encrypted in transit and at rest using industry-standard protocols.

  • Access Control: Access is restricted to authorized personnel only.

  • Secure Hosting: Our Service is hosted on SOC 2-compliant infrastructure, which is continuously monitored and audited.

7. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law.

  • For the Service: End User data is retained according to our customer's instructions and will be deleted or returned within 30 days after the termination of the Service, unless otherwise required by law.

  • For Website Data: Data from leads and traffic analysis is kept for a reasonable period to manage commercial activities and analytics unless a deletion request is received.

8. Rights of Data Subjects

8.1 For Service Users (End Users)

Since our customers act as Data Controllers in the Service context, End Users should direct any requests to access, correct, or delete their personal data to their employer. Pensero will assist the customer in responding to such requests only as instructed in writing.

8.2 For Website Visitors (Potential Customers)

Visitors who provide their personal data via our website have rights to access, correct, delete, restrict processing, request portability, or object to the processing of their data. Such requests can be submitted directly using the contact details below.

9. Exercising Your Rights

For any inquiries or to exercise your rights regarding your personal data:

  • Service Users: Please contact your employer's Data Protection Officer or responsible team/person.

  • Website Visitors: Please contact Pensero at:

Pensero will, where permitted by law, assist in exercising these rights and maintain records of requests to ensure compliance.

II. Jurisdiction-Specific Sections

The following provisions apply in addition to the Generic Section, depending on the applicable legal framework.

1. USA Data Protection Provisions

Scope: This section applies when personal data processing involves U.S. consumers or is subject to U.S. privacy laws, such as the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

Requirements:

  • Data is processed solely for the above purposes and following the customer's instructions (for the Service) or legitimate commercial purposes (for the website).

  • Sale and sharing of personal information: We do not sell your personal information for money. However, our use of advertising and analytics cookies to measure and deliver marketing may be considered a "sale" or "sharing" of personal information under the CCPA and CPRA, because online identifiers may be disclosed to advertising partners for cross-context behavioral advertising. You have the right to opt out. You can do so by (i) using the "Do Not Sell or Share My Personal Information" link on our website, (ii) rejecting advertising cookies in our cookie banner, or (iii) enabling a Global Privacy Control (GPC) signal in your browser, which we honor.

  • Consumer rights (such as access, correction, and deletion) will be respected, along with the right to be free from discrimination for exercising them. Any requests from U.S. consumers will be promptly communicated to the appropriate contact.

2. UK Data Protection Provisions

Scope: This section applies when personal data processing is subject to UK data protection laws, including the UK General Data Protection Regulation (UK GDPR).

Requirements:

  • Data processing will be conducted following the principles of lawfulness, fairness, and transparency.

  • Pensero will cooperate with the customer to ensure that data subject rights (access, rectification, deletion, etc.) are fully respected.

  • Any international data transfers outside the UK will be subject to the necessary safeguards under the UK GDPR.

3. GDPR Provisions (EU)

Scope: This section applies when personal data processing is governed by the European Union's General Data Protection Regulation (GDPR).

Requirements:

  • Pensero processes data strictly according to the customer's documented instructions and on a lawful basis under the GDPR.

  • Data subject rights (access, rectification, deletion, restriction, portability, and objection) are guaranteed, and Pensero will assist the customer in fulfilling these rights.

  • Any Subprocessors engaged by Pensero will be contractually obligated to uphold protections equivalent to those in this Privacy Policy.

  • Where required, Pensero will cooperate with the customer to conduct Data Protection Impact Assessments (DPIAs).

III. Changes to This Privacy Policy

Pensero may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated to our customers, and the updated effective date will be indicated at the top of this document.

IV. Contact Us

For any questions regarding this Privacy Policy or our data protection practices, please contact:

Pensero Inc.
Email: datarequests@pensero.ai
Address: 169 Madison Ave, STE 2998, New York, NY 10016