This privacy policy describes the processing of personal data by Audienca
Reflection, including the /mcp endpoint. It applies to use through the
Audienca interface, ChatGPT or another MCP client, and integrations activated
by users.
1. Data Controller
senseaition GmbHSchmiedestr. 2a, 15745 Wildau, Germany
Phone: +49 (0)3375 280 7666
Email: info@senseaition.com
Commercial register: Cottbus Local Court, HRB 13691 CB
VAT ID: DE319254633
The data controller is senseaition GmbH.
2. Data Protection Officer
Dr. Matthias Boldt
Email: datenschutz@senseaition.com
3. Hosting and Processors
Audienca Reflection runs on servers of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in a German datacenter. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
For AI-based response generation, we use the internal sm-generativetext
service. Depending on the production configuration, it may use external models
such as the OpenAI API (OpenAI OpCo, LLC, 3180 18th Street, San Francisco, CA
94110, USA). In that case, data transfers to the USA are based on the EU
Standard Contractual Clauses and a Data Processing Addendum (DPA). OpenAI does
not use submitted API data to train the underlying models, in accordance with
its enterprise terms.
For MCP and other LLM functions, sm-generativetext may be used for LLM
generation, classification, evaluation, and embeddings. Inquiry content,
project context, knowledge-base excerpts, and configuration rules may be
transferred. Audienca data is not used for training or model improvement; it is
processed solely to provide the analysis, retrieval, evaluation, and generation
functions requested by users.
Other possible service providers include Redis for short-lived OAuth, session, synchronization, cache, and queue data; object/file storage and a vector database for uploads and knowledge resources; Firebase Authentication for sign-in; Sentry and OpenTelemetry for error, security, and performance monitoring; and united-domains GmbH for transactional email and notifications, where these services are used for Audienca Reflection.
4. Data Processed on Website Access
When accessing audienca.com, the following data is processed in server log files:
- IP address (truncated where possible)
- Date and time of access
- URL accessed
- Referrer URL
- Browser and operating system
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and stability). Retention: as long as technically and security-relevant; then deleted.
5. Cookies and Tracking
We use technically necessary cookies and, with explicit consent, cookies for statistics and marketing. Consent is collected via the consent banner and may be revoked at any time.
5.1 Statistics
- Rybbit — self-hosted web analytics on analytics.senseaition.com. No personal data leaves our infrastructure.
- Mouseflow — provider: Mouseflow ApS, Flæsketorvet 68, 1711 Copenhagen, Denmark. Purpose: session replay and heatmaps for usability research. User input is anonymized. Privacy notice: mouseflow.com/legal/privacy.
- Sentry — self-hosted error monitoring on sentry.senseaition.com. No third-party transfer.
5.2 Marketing
- Meta Pixel — provider: Meta Platforms Ireland Ltd. Purpose: conversion measurement of ads. Privacy notice: facebook.com/privacy/policy.
6. Account and Service Use
When registering for Audienca Reflection, we process:
- Email address, name, optional phone number
- Company, role
- Payment information (processed exclusively by Stripe Payments Europe Limited)
Legal basis: Art. 6(1)(b) GDPR (contract fulfilment).
Depending on the enabled features, we may also process Firebase user IDs, customer/tenant IDs, API key or bearer/OAuth credentials, OAuth client metadata, consent and session data, IP addresses, timestamps, project and permission data, prompts, response and evaluation rules, labels, audit events, trace and performance data, progress messages, generated response drafts, TwentyFive profiles, uploaded files, extracted text, chunks, embeddings/vector data, synchronization settings, and technical LLM telemetry.
Users should not submit special categories of personal data, passwords, ID documents, health data, or secret credentials in inquiry text, files, prompts, or comments.
7. Customer Inquiries and Responses
Audienca processes customer messages ingested via integrations (Google Business Profile, Meta, Trusted Shops, IMAP, etc.) exclusively under the Data Processing Agreement (Art. 28 GDPR), available at audienca.com/en/orderprocessing.
7.1 Processing through MCP tools
An MCP client sends user-triggered tool inputs to Audienca. Inputs may include project and inquiry IDs, filters, free text, file contents or storage IDs, email addresses, labels, configurations, and actions. Audienca returns structured results, status values, inquiry data, generated drafts, statistics, analysis values, file and resource metadata, and error or progress information to the MCP client.
The tools serve the following purposes:
- Creating, importing, listing, retrieving, filtering, analyzing, comparing, rating, editing, archiving, or deleting inquiries
- Creating, improving, regenerating, and rating response drafts and variants with an LLM
- Selecting responses, marking them as answered or closed, or — only after an explicit action — sending them to the source platform
- Moderating comments on supported source platforms (deleting, hiding, showing, liking, pinning, or blocking the author)
- Managing projects, labels, rules, notifications, synchronizations, and generation/analysis configurations
- Uploading files and creating, retrieving, or deleting knowledge resources, including vector data
Read tools do not change stored data. Write tools modify the authenticated
Audienca project. Actions such as sendAnswer, external comment moderation,
and deletion may additionally change a third party’s system or irreversibly
remove data. They require the appropriate audienca:write permission and,
where applicable, an active Reflection permission.
The MCP client, such as ChatGPT, may store tool inputs and outputs under its own privacy policy. Audienca receives only the data submitted by the client for the relevant call; processing within the client is outside Audienca’s control.
7.2 Purposes and legal bases
We process data to provide Audienca Reflection, manage inquiries and projects, generate response drafts, retrieve knowledge resources, synchronize integrations, execute requested messaging or moderation actions, ensure security and prevent misuse, troubleshoot errors, and measure performance.
Depending on the relationship and purpose, the legal bases are Art. 6(1)(b) GDPR (contract/requested service), Art. 6(1)(f) GDPR (security, operation, and troubleshooting), and Art. 6(1)(a) GDPR (consent, particularly for optional integrations). For data entered into the product by a company, that company generally remains the controller; senseaition processes the data as a processor under its contractual instructions.
7.3 Recipients and service providers
Data is disclosed only where necessary for the stated purposes or where
required by law. Possible recipients and processors include the Audienca/SM
API and database operated by senseaition, Redis, object/file storage, a vector
database, sm-generativetext, source platforms and their APIs activated by the
user (including Google, Meta/Facebook/Instagram, YouTube, Trustpilot, Trusted
Shops, eKomi, Google Play, LinkedIn, the App Store, and IMAP), Firebase
Authentication, Sentry, OpenTelemetry, Hetzner Online GmbH, united-domains
GmbH, and Stripe Payments Europe Limited, where these services are used.
Data transfers to third countries take place only on an appropriate legal basis (such as an adequacy decision or Standard Contractual Clauses) and with the required safeguards. The concrete providers, regions, and transfer mechanisms must be kept current in the published subprocessor list.
7.4 Retention and deletion
- Project data is deleted according to the retention days displayed and configured for the relevant project, including data, orders/history, personal references, and results. When a project is created through MCP, the current default is 30 days; users can change these values. Existing or otherwise created projects use their stored values.
- An inquiry can be deleted through
delete_inquiry, a knowledge resource throughdelete_resource, and integration or automation configurations through their respective deletion tools. Deleting an inquiry is irreversible; copies in source systems are not automatically removed. - OAuth authorization codes expire after 5 minutes, pending authorization flows after 15 minutes, access tokens after 1 hour, refresh tokens after 90 days (with rotation), and registered OAuth clients after 365 days. Tokens are stored only as hashes.
- Short-lived check, session, and cache data have fixed periods depending on
the function, including 2 hours or 7 days. Persisted public check results
are controlled by
CHECK_RESULT_TTL_HOURS; a value of 0 or empty currently means unlimited retention. - Backups, security logs, Sentry/trace data, and legally required records are retained only as long as necessary for the stated purposes or as required by law.
After the retention period, data is deleted or anonymized unless a statutory retention obligation, an unresolved legal claim, or a technically necessary backup window prevents this.
7.5 User controls
Users can minimize data, disable optional integrations, adjust retention days, decline to send drafts, stop synchronizations, and delete existing projects, inquiries, resources, and rules through the interface or MCP deletion tools. An explicit user action is required before external publication or moderation actions.
7.6 Security
Access is authenticated and restricted through scopes. Write access requires
audienca:write; projects and data are checked for tenant isolation. Transfers
are encrypted, tokens are stored as hashes, and deletion or modification
actions are logged. No security procedure is absolute; users must protect
their credentials and report suspicious activity without delay.
Technical and organizational measures include TLS/HTTPS, access restrictions and role/permission checks, regular security updates, encryption of data stores where possible, backups, incident response procedures, and employee awareness training.
7.7 Current MCP interface
As of the date of this policy, the MCP interface includes the following tools:
analyze_inquiry_themes, augment_inquiry_response, batch_create_inquiries,
bulk_update_inquiries, compare_inquiry_segments, create_automation_rule,
create_inquiry, create_inquiry_variations, create_project,
create_resource, create_sync_config, delete_automation_rule,
delete_inquiry, delete_resource, delete_sync_config, edit_project,
get_inquiries_batch, get_inquiry, get_inquiry_audit_log,
get_inquiry_by_external_id, get_inquiry_stats, get_notification_config,
get_project, get_project_config, get_resource,
get_response_performance, list_automation_rules, list_inquiries,
list_inquiries_v2, list_label_catalog, list_projects, list_resources,
list_sync_configs, moderate_inquiry_message, rate_inquiry_variation,
regenerate_inquiry, reorder_automation_rules, set_inquiry_state,
trigger_integration_sync, update_analysis_config, update_automation_rule,
update_config_sections, update_eval_config, update_generation_config,
update_inquiry_metadata, update_notification_config,
update_project_settings, update_sync_config, upload_file,
upsert_direct_message, and use_inquiry_variation.
This policy must be updated before the next publication whenever tool names, input schemas, output fields, recipients, or side effects change.
7.8 LLM providers and model improvement
For LLM functions, we process inputs (including prompts, relevant inquiry
content, and retrieved knowledge-base excerpts) and generated outputs. The
internal sm-generativetext service may use external models such as the
OpenAI API, depending on the production configuration. In that case, OpenAI
must be included as a processor under its applicable privacy terms and Data
Processing Addendum; transfers to the USA or other third countries may occur.
Audienca data is not used for training or model improvement.
8. Rights of Data Subjects
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21 GDPR). Please contact info@senseaition.com or our Data Protection Officer.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for our company is:
Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht BrandenburgStahnsdorfer Damm 77
14532 Kleinmachnow, Germany
Phone: +49 33203 356-0
Email: poststelle@lda.brandenburg.de
9. Changes
We update this privacy policy when legal or factual changes occur, particularly when functions, tool inputs, tool outputs, recipients, or retention periods change. The latest version, identified by its date, is always available at this URL.